Add a nonce to wp_ajax_save_attachment. see #21390, #21807.

git-svn-id: http://core.svn.wordpress.org/trunk@22212 1a063a9b-81f0-0310-95a4-ce76da25c4cd
This commit is contained in:
Daryl Koopersmith
2012-10-12 16:02:45 +00:00
parent fa4b36948a
commit 3ee553c6bc
3 changed files with 12 additions and 2 deletions

View File

@@ -315,6 +315,10 @@ function wp_default_scripts( &$scripts ) {
) );
$scripts->add( 'media-models', "/wp-includes/js/media-models$suffix.js", array( 'backbone', 'jquery' ), false, 1 );
did_action( 'init' ) && $scripts->localize( 'media-models', '_wpMediaModelsL10n', array(
'saveAttachmentNonce' => wp_create_nonce( 'save-attachment' ),
) );
$scripts->add( 'media-views', "/wp-includes/js/media-views$suffix.js", array( 'media-models', 'wp-plupload' ), false, 1 );
did_action( 'init' ) && $scripts->localize( 'media-views', '_wpMediaViewsL10n', array(
// Generic