@@ -1891,7 +1891,7 @@ public static function getWallPostComments(
1891
1891
1892
1892
$ formattedList .= '</div> ' ;
1893
1893
$ formattedList .= '<div class="mediapost-form row"> ' ;
1894
- $ formattedList .= '<form class="form-horizontal" id="form_comment_ ' .$ messageId .'" name="post_comment" method="POST">
1894
+ $ formattedList .= '<form class="form-horizontal" id="form_comment_ ' .$ messageId .'" name="post_comment" method="POST" data-sec-token=" ' .Security:: get_existing_token ( ' wall ' ). ' " >
1895
1895
<div class="col-sm-9">
1896
1896
<label for="comment" class="hide"> ' .get_lang ('SocialWriteNewComment ' ).'</label>
1897
1897
<input type="hidden" name = "messageId" value=" ' .$ messageId .'" />
@@ -1902,6 +1902,7 @@ public static function getWallPostComments(
1902
1902
<em class="fa fa-pencil"></em> ' .get_lang ('Post ' ).'
1903
1903
</a>
1904
1904
</div>
1905
+ <input type="hidden" name="wall_sec_token" value=" ' .Security::get_existing_token ('wall ' ).'">
1905
1906
</form> ' ;
1906
1907
$ formattedList .= '</div> ' ;
1907
1908
@@ -3021,15 +3022,18 @@ public static function getScrollJs($countPost, &$htmlHeadXtra)
3021
3022
$ htmlHeadXtra [] = '<script>
3022
3023
function submitComment(messageId)
3023
3024
{
3024
- var data = $("#form_comment_"+messageId).serializeArray();
3025
+ var $form = $("#form_comment_"+messageId);
3026
+ var data = $form.serializeArray();
3025
3027
$.ajax({
3026
3028
type : "POST",
3027
- url: " ' .$ socialAjaxUrl .'?a=send_comment" + "&id=" + messageId,
3029
+ url: " ' .$ socialAjaxUrl .'?a=send_comment" + "&id=" + messageId + "&wall_sec_token=" + $form.data("sec-token") ,
3028
3030
data: data,
3029
3031
success: function (result) {
3030
3032
if (result) {
3033
+ $(".mediapost-form form").data({ "sec-token": result.secToken });
3034
+
3031
3035
$("#post_" + messageId + " textarea").val("");
3032
- $("#post_" + messageId + " .sub-mediapost").prepend(result);
3036
+ $("#post_" + messageId + " .sub-mediapost").prepend(result.postHTML );
3033
3037
$("#post_" + messageId + " .sub-mediapost").append(
3034
3038
$( \'<div id=result_ \' + messageId + \'> ' .addslashes (get_lang ('Saved ' )).'</div> \')
3035
3039
);
0 commit comments