|
@@ 281-283 (lines=3) @@
|
| 278 |
|
|
| 279 |
|
// CSRF check |
| 280 |
|
$token = SecurityToken::inst(); |
| 281 |
|
if (empty($vars[$token->getName()]) || !$token->check($vars[$token->getName()])) { |
| 282 |
|
return new HTTPResponse(null, 400); |
| 283 |
|
} |
| 284 |
|
|
| 285 |
|
if (!isset($vars['ids']) || !$vars['ids']) { |
| 286 |
|
return (new HTTPResponse(json_encode(['status' => 'error']), 400)) |
|
@@ 327-329 (lines=3) @@
|
| 324 |
|
|
| 325 |
|
// CSRF check |
| 326 |
|
$token = SecurityToken::inst(); |
| 327 |
|
if (empty($data[$token->getName()]) || !$token->check($data[$token->getName()])) { |
| 328 |
|
return new HTTPResponse(null, 400); |
| 329 |
|
} |
| 330 |
|
|
| 331 |
|
// Check parent record |
| 332 |
|
/** @var Folder $parentRecord */ |
|
@@ 407-409 (lines=3) @@
|
| 404 |
|
|
| 405 |
|
// CSRF check |
| 406 |
|
$token = SecurityToken::inst(); |
| 407 |
|
if (empty($data[$token->getName()]) || !$token->check($data[$token->getName()])) { |
| 408 |
|
return new HTTPResponse(null, 400); |
| 409 |
|
} |
| 410 |
|
|
| 411 |
|
// check addchildren permissions |
| 412 |
|
/** @var Folder $parentRecord */ |