}\r
}\r
\r
- if (get_plugin_setting('download_link', 'tidypics') != "disabled") { \r
+ if (get_plugin_setting('download_link', 'tidypics') != "disabled") {\r
+ $ts = time();\r
+ $token = generate_action_token($ts);\r
+ \r
+ $download_url = $vars['url'] . "action/tidypics/download?file_guid=" . $image_guid . "&__elgg_token=$token&__elgg_ts=$ts"; \r
?>\r
-<li id="download_image"><a href="<?php echo $vars['url']; ?>action/tidypics/download?file_guid=<?php echo $image_guid; ?>"><?php echo elgg_echo("image:download"); ?></a></li>\r
+<li id="download_image"><a href="<?php echo $download_url; ?>"><?php echo elgg_echo("image:download"); ?></a></li>\r
<?php\r
} \r
?>
\ No newline at end of file