|
@@ 344-346 (lines=3) @@
|
| 341 |
|
|
| 342 |
|
// CSRF check |
| 343 |
|
$token = SecurityToken::inst(); |
| 344 |
|
if (empty($vars[$token->getName()]) || !$token->check($vars[$token->getName()])) { |
| 345 |
|
return new HTTPResponse(null, 400); |
| 346 |
|
} |
| 347 |
|
|
| 348 |
|
if (!isset($vars['ids']) || !$vars['ids']) { |
| 349 |
|
return (new HTTPResponse(json_encode(['status' => 'error']), 400)) |
|
@@ 390-392 (lines=3) @@
|
| 387 |
|
|
| 388 |
|
// CSRF check |
| 389 |
|
$token = SecurityToken::inst(); |
| 390 |
|
if (empty($data[$token->getName()]) || !$token->check($data[$token->getName()])) { |
| 391 |
|
return new HTTPResponse(null, 400); |
| 392 |
|
} |
| 393 |
|
|
| 394 |
|
// Check parent record |
| 395 |
|
/** @var Folder $parentRecord */ |
|
@@ 566-568 (lines=3) @@
|
| 563 |
|
|
| 564 |
|
// CSRF check |
| 565 |
|
$token = SecurityToken::inst(); |
| 566 |
|
if (empty($data[$token->getName()]) || !$token->check($data[$token->getName()])) { |
| 567 |
|
return new HTTPResponse(null, 400); |
| 568 |
|
} |
| 569 |
|
|
| 570 |
|
// check addchildren permissions |
| 571 |
|
/** @var Folder $parentRecord */ |