|
@@ 525-527 (lines=3) @@
|
| 522 |
|
|
| 523 |
|
// CSRF check |
| 524 |
|
$token = SecurityToken::inst(); |
| 525 |
|
if (empty($data[$token->getName()]) || !$token->check($data[$token->getName()])) { |
| 526 |
|
return new HTTPResponse(null, 400); |
| 527 |
|
} |
| 528 |
|
|
| 529 |
|
// check addchildren permissions |
| 530 |
|
/** @var Folder $parentRecord */ |
|
@@ 301-303 (lines=3) @@
|
| 298 |
|
|
| 299 |
|
// CSRF check |
| 300 |
|
$token = SecurityToken::inst(); |
| 301 |
|
if (empty($vars[$token->getName()]) || !$token->check($vars[$token->getName()])) { |
| 302 |
|
return new HTTPResponse(null, 400); |
| 303 |
|
} |
| 304 |
|
|
| 305 |
|
if (!isset($vars['ids']) || !$vars['ids']) { |
| 306 |
|
return (new HTTPResponse(json_encode(['status' => 'error']), 400)) |
|
@@ 347-349 (lines=3) @@
|
| 344 |
|
|
| 345 |
|
// CSRF check |
| 346 |
|
$token = SecurityToken::inst(); |
| 347 |
|
if (empty($data[$token->getName()]) || !$token->check($data[$token->getName()])) { |
| 348 |
|
return new HTTPResponse(null, 400); |
| 349 |
|
} |
| 350 |
|
|
| 351 |
|
// Check parent record |
| 352 |
|
/** @var Folder $parentRecord */ |