Koha/opac/opac-ratings.pl
Fridolin Somers f1acb5615d Bug 14440: get_template_and_user can not have an empty template_name (opac-ratings.pl)
Since Bug 14408, the method get_template_and_user can not have an empty template_name.
Pages calling with an empty value should use C4::Auth::checkauth()

This patch corrects opac/opac-ratings.pl

Test plan :
- Apply patch
- Set sysopref OpacStarRatings to 'results and details'
- Disable Javascipt on your browser (otherwise it will use ajax)
- Login at OPAC
- Go to a record
- Click on a button left of 'Rate me' to choose a rating, ie 4
- Click on 'Rate me'
=> The page is reloaded and you see 'your rating: 4'
- Loggout from OPAC
- Try to access URL : http://<serveur>/cgi-bin/koha/opac-ratings.pl
=> You see the loggin page

Signed-off-by: Indranil Das Gupta (L2C2 Technologies) <indradg@gmail.com>
Signed-off-by: Tomas Cohen Arazi <tomascohen@theke.io>
Signed-off-by: Katrin Fischer <katrin.fischer@bsz-bw.de>
Signed-off-by: Tomas Cohen Arazi <tomascohen@unc.edu.ar>
2015-06-25 14:41:21 -03:00

55 lines
1.6 KiB
Perl
Executable file

#!/usr/bin/perl
# Copyright 2011 KohaAloha, NZ
#
# This file is part of Koha.
#
# Koha is free software; you can redistribute it and/or modify it
# under the terms of the GNU General Public License as published by
# the Free Software Foundation; either version 3 of the License, or
# (at your option) any later version.
#
# Koha is distributed in the hope that it will be useful, but
# WITHOUT ANY WARRANTY; without even the implied warranty of
# MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
# GNU General Public License for more details.
#
# You should have received a copy of the GNU General Public License
# along with Koha; if not, see <http://www.gnu.org/licenses>.
=head1
A non-javascript method to add/modify a biblio's rating, called from opac-detail.pl
note: there is currently no 'delete rating' functionality in this script
=cut
use strict;
use warnings;
use CGI qw ( -utf8 );
use C4::Auth;
use C4::Context;
use C4::Ratings;
use C4::Debug;
my $query = CGI->new();
# auth required to add ratings
my ($userid, $cookie, $sessionID) = checkauth( $query, 0, {}, 'opac' );
my $loggedinuser = C4::Context->userenv->{'number'};
my $biblionumber = $query->param('biblionumber');
my $rating_old_value = $query->param('rating_value');
my $rating_value = $query->param('rating');
my $rating;
if ( !$rating_old_value ) {
$rating = AddRating( $biblionumber, $loggedinuser, $rating_value );
}
else {
$rating = ModRating( $biblionumber, $loggedinuser, $rating_value );
}
print $query->redirect(
"/cgi-bin/koha/opac-detail.pl?biblionumber=$biblionumber");