|
@@ 337-339 (lines=3) @@
|
| 334 |
|
|
| 335 |
|
// CSRF check |
| 336 |
|
$token = SecurityToken::inst(); |
| 337 |
|
if (empty($vars[$token->getName()]) || !$token->check($vars[$token->getName()])) { |
| 338 |
|
return new HTTPResponse(null, 400); |
| 339 |
|
} |
| 340 |
|
|
| 341 |
|
if (!isset($vars['ids']) || !$vars['ids']) { |
| 342 |
|
return (new HTTPResponse(json_encode(['status' => 'error']), 400)) |
|
@@ 383-385 (lines=3) @@
|
| 380 |
|
|
| 381 |
|
// CSRF check |
| 382 |
|
$token = SecurityToken::inst(); |
| 383 |
|
if (empty($data[$token->getName()]) || !$token->check($data[$token->getName()])) { |
| 384 |
|
return new HTTPResponse(null, 400); |
| 385 |
|
} |
| 386 |
|
|
| 387 |
|
// Check parent record |
| 388 |
|
/** @var Folder $parentRecord */ |
|
@@ 560-562 (lines=3) @@
|
| 557 |
|
|
| 558 |
|
// CSRF check |
| 559 |
|
$token = SecurityToken::inst(); |
| 560 |
|
if (empty($data[$token->getName()]) || !$token->check($data[$token->getName()])) { |
| 561 |
|
return new HTTPResponse(null, 400); |
| 562 |
|
} |
| 563 |
|
|
| 564 |
|
// check addchildren permissions |
| 565 |
|
/** @var Folder $parentRecord */ |