Well, this time I got the error message in english anyway
Quote:
Your submission could not be processed because a security token was missing.
|
Just to clearify everything.
I have created a widget (PHP Direct Execution) with this content:
PHP Code:
// UNTESTED
ob_start();
include("test/addApplication.php");
echo "<br />\n";
$output .= ob_get_contents();
ob_end_clean();
the file (addApplication.php) that the widget refers to is this:
PHP Code:
<?php
if(isset($_POST['add_Application_Submit']))
{
include 'dbConnection.php';
$firstname = get_magic_quotes_gpc($_POST['add_Application_Firstname']);
$lastname = get_magic_quotes_gpc($_POST['add_Application_Lastname']);
$mobilephone = get_magic_quotes_gpc($_POST['add_Application_Mobilephone']);
$pnumber = get_magic_quotes_gpc($_POST['add_Application_p-number']);
$bnumber = get_magic_quotes_gpc($_POST['add_Application_b-number']);
$dnumber = get_magic_quotes_gpc($_POST['add_Application_d-number']);
$distict = get_magic_quotes_gpc($_POST['add_Application_district']);
$userID = get_magic_quotes_gpc($_POST['add_Application_UserID']);
$presentation = get_magic_quotes_gpc($_POST['add_Application_Presentation']);
$status = "0";
$query = "INSERT INTO ovse_applications (firstName, lastName, mobile, p-number, b-number, d-number, district, userID, presentation, application_status) VALUES ($firstname, $lastname, $mobilephone, $pnumber, $bnumber, $dnumber, $district, $userID, $presentation, $status)";
mysql_query($query) or die('Error, insert query failed');
$query = "FLUSH PRIVILEGES";
mysql_query($query) or die('Error, insert query failed');
mysql_close($conn);
echo "New MySQL user added";
}
else
{
?>
<form id="form1" method="post" action="">
<table border="0" cellpadding="0" cellspacing="0">
<tr>
<td> Förnamn </td>
<td><input type="text" name="add_Application_Firstname" id="add_Application_Firstname" /></td>
</tr>
<tr>
<td> Efternamn </td>
<td><input type="text" name="add_Application_Lastname" id="add_Application_Lastname" /></td>
</tr>
<tr>
<td>Mobilnummer: </td>
<td><input type="text" name="add_Application_Mobilephone" id="add_Application_Mobilephone" /></td>
</tr>
<tr>
<td>Personnummer: </td>
<td><input type="text" name="add_Application_p-number" id="add_Application_p-number" /></td>
</tr>
<tr>
<td>Bricknummer: </td>
<td><input type="text" name="add_Application_b-number" id="add_Application_b-number" /></td>
</tr>
<tr>
<td>Diarienummer: </td>
<td><input type="text" name="add_Application_d-number" id="add_Application_d-number" /></td>
</tr>
<tr>
<td>Län: </td>
<td><select name="add_Application_district" id="add_Application_district">
<option value="Inget län valt">Inget län valt</option>
<option value="Blekinge">Blekinge</option>
<option value="Dalarna">Dalarna</option>
<option value="Gotlands län">Gotlands län</option>
<option value="Gävleborg">Gävleborg</option>
<option value="Halland">Halland</option>
<option value="Jämtland">Jämtland</option>
<option value="Jönköpings län">Jönköpings län</option>
<option value="Kalmar län">Kalmar län</option>
<option value="Kronoberg">Kronoberg</option>
<option value="Norrbotten">Norrbotten</option>
<option value="Skåne">Skåne</option>
<option value="Stockholms län">Stockholms län</option>
<option value="Södermanland">Södermanland</option>
<option value="Uppsala län">Uppsala län</option>
<option value="Värmland">Värmland</option>
<option value="Västerbotten">Västerbotten</option>
<option value="Västernorrland">Västernorrland</option>
<option value="Västmanland">Västmanland</option>
<option value="Västra Götaland">Västra Götaland</option>
<option value="Örebro län">Örebro län</option>
<option value="Östergötland">Östergötland</option>
</select>
<input name="add_Application_UserID" type="hidden" id="add_Application_UserID" value="<? print(vB::$vbulletin->userinfo['userid']); ?>" />
<input type="hidden" name="securitytoken" value="<?php echo $bbuserinfo['securitytoken']; ?>" />
</td>
</tr>
<tr>
<td>Kort personlig presentation:</td>
<td><textarea name="add_Application_Presentation" rows="10" id="add_Application_Presentation"></textarea></td>
</tr>
<tr>
<td> </td>
<td><input type="submit" name="add_Application_Submit" id="add_Application_Submit" value="Ansök" /></td>
</tr>
</table>
</form>
<?php
}
?>
Quote:
Originally Posted by BBR-APBT
on a plus note the code is not with in the PHP braces so its basicly html. You might need to do
Code:
<input type="hidden" name="securitytoken" value="<?php echo $bbuserinfo['securitytoken']; ?>" />
|
Edit: If I do a simple <?php echo $bbuserinfo['securitytoken']; ?>, it dosen't show anything, but that's maybe normal?