|
@@ 306-308 (lines=3) @@
|
| 303 |
|
|
| 304 |
|
// CSRF check |
| 305 |
|
$token = SecurityToken::inst(); |
| 306 |
|
if (empty($vars[$token->getName()]) || !$token->check($vars[$token->getName()])) { |
| 307 |
|
return new HTTPResponse(null, 400); |
| 308 |
|
} |
| 309 |
|
|
| 310 |
|
if (!isset($vars['ids']) || !$vars['ids']) { |
| 311 |
|
return (new HTTPResponse(json_encode(['status' => 'error']), 400)) |
|
@@ 352-354 (lines=3) @@
|
| 349 |
|
|
| 350 |
|
// CSRF check |
| 351 |
|
$token = SecurityToken::inst(); |
| 352 |
|
if (empty($data[$token->getName()]) || !$token->check($data[$token->getName()])) { |
| 353 |
|
return new HTTPResponse(null, 400); |
| 354 |
|
} |
| 355 |
|
|
| 356 |
|
// Check parent record |
| 357 |
|
/** @var Folder $parentRecord */ |
|
@@ 529-531 (lines=3) @@
|
| 526 |
|
|
| 527 |
|
// CSRF check |
| 528 |
|
$token = SecurityToken::inst(); |
| 529 |
|
if (empty($data[$token->getName()]) || !$token->check($data[$token->getName()])) { |
| 530 |
|
return new HTTPResponse(null, 400); |
| 531 |
|
} |
| 532 |
|
|
| 533 |
|
// check addchildren permissions |
| 534 |
|
/** @var Folder $parentRecord */ |