Add a nonce to wp_ajax_save_attachment. see #21390, #21807.

git-svn-id: https://develop.svn.wordpress.org/trunk@22212 602fd350-edb4-49c9-b593-d223f7449a82
This commit is contained in:
Daryl Koopersmith
2012-10-12 16:02:45 +00:00
parent 678b2e0695
commit 990d50661c
3 changed files with 12 additions and 2 deletions

View File

@@ -315,6 +315,10 @@ function wp_default_scripts( &$scripts ) {
) );
$scripts->add( 'media-models', "/wp-includes/js/media-models$suffix.js", array( 'backbone', 'jquery' ), false, 1 );
did_action( 'init' ) && $scripts->localize( 'media-models', '_wpMediaModelsL10n', array(
'saveAttachmentNonce' => wp_create_nonce( 'save-attachment' ),
) );
$scripts->add( 'media-views', "/wp-includes/js/media-views$suffix.js", array( 'media-models', 'wp-plupload' ), false, 1 );
did_action( 'init' ) && $scripts->localize( 'media-views', '_wpMediaViewsL10n', array(
// Generic