|
@@ 298-300 (lines=3) @@
|
| 295 |
|
|
| 296 |
|
// CSRF check |
| 297 |
|
$token = SecurityToken::inst(); |
| 298 |
|
if (empty($vars[$token->getName()]) || !$token->check($vars[$token->getName()])) { |
| 299 |
|
return new HTTPResponse(null, 400); |
| 300 |
|
} |
| 301 |
|
|
| 302 |
|
if (!isset($vars['ids']) || !$vars['ids']) { |
| 303 |
|
return (new HTTPResponse(json_encode(['status' => 'error']), 400)) |
|
@@ 344-346 (lines=3) @@
|
| 341 |
|
|
| 342 |
|
// CSRF check |
| 343 |
|
$token = SecurityToken::inst(); |
| 344 |
|
if (empty($data[$token->getName()]) || !$token->check($data[$token->getName()])) { |
| 345 |
|
return new HTTPResponse(null, 400); |
| 346 |
|
} |
| 347 |
|
|
| 348 |
|
// Check parent record |
| 349 |
|
/** @var Folder $parentRecord */ |
|
@@ 520-522 (lines=3) @@
|
| 517 |
|
|
| 518 |
|
// CSRF check |
| 519 |
|
$token = SecurityToken::inst(); |
| 520 |
|
if (empty($data[$token->getName()]) || !$token->check($data[$token->getName()])) { |
| 521 |
|
return new HTTPResponse(null, 400); |
| 522 |
|
} |
| 523 |
|
|
| 524 |
|
// check addchildren permissions |
| 525 |
|
/** @var Folder $parentRecord */ |