X-Git-Url: https://scripts.mit.edu/gitweb/autoinstalls/wordpress.git/blobdiff_plain/5aa86a9053fb0fa15846bb60aac2fb8fdfff524a..refs/tags/wordpress-3.4:/wp-admin/media-upload.php diff --git a/wp-admin/media-upload.php b/wp-admin/media-upload.php index 666c3f37..6246176b 100644 --- a/wp-admin/media-upload.php +++ b/wp-admin/media-upload.php @@ -22,6 +22,7 @@ wp_enqueue_script('plupload-handlers'); wp_enqueue_script('image-edit'); wp_enqueue_script('set-post-thumbnail' ); wp_enqueue_style('imgareaselect'); +wp_enqueue_script( 'media-gallery' ); @header('Content-Type: ' . get_option('html_type') . '; charset=' . get_option('blog_charset')); @@ -31,11 +32,14 @@ $post_id = isset($post_id)? (int) $post_id : 0; // Require an ID for the edit screen if ( isset($action) && $action == 'edit' && !$ID ) - wp_die(__("You are not allowed to be here")); + wp_die( __( 'Cheatin’ uh?' ) ); if ( isset($_GET['inline']) ) { $errors = array(); + if ( ! empty( $_REQUEST['post_id'] ) && ! current_user_can( 'edit_post' , $_REQUEST['post_id'] ) ) + wp_die( __( 'Cheatin’ uh?' ) ); + if ( isset($_POST['html-upload']) && !empty($_FILES) ) { check_admin_referer('media-form'); // Upload File button was clicked @@ -58,6 +62,9 @@ if ( isset($_GET['inline']) ) { exit; } + if ( isset( $_REQUEST['post_id'] ) ) + wp_die( __( 'Cheatin’ uh?' ) ); + $title = __('Upload New Media'); $parent_file = 'upload.php'; get_current_screen()->add_help_tab( array( @@ -67,8 +74,8 @@ if ( isset($_GET['inline']) ) { '

' . __('You can upload media files here without creating a post first. This allows you to upload files to use with posts and pages later and/or to get a web link for a particular file that you can share. There are three options for uploading files:') . '

' . '' . '

' . __('Basic image editing is available after upload is complete. Make sure you click Save before leaving this screen.') . '

' ) ); @@ -115,6 +122,8 @@ if ( isset($_GET['inline']) ) { include('./admin-footer.php'); } else { + if ( ! empty( $_REQUEST['post_id'] ) && ! current_user_can( 'edit_post' , $_REQUEST['post_id'] ) ) + wp_die( __( 'Cheatin’ uh?' ) ); // upload type: image, video, file, ..? if ( isset($_GET['type']) ) @@ -136,4 +145,3 @@ if ( isset($_GET['inline']) ) { else do_action("media_upload_$tab"); } -?>