|
@@ 320-322 (lines=3) @@
|
| 317 |
|
|
| 318 |
|
// CSRF check |
| 319 |
|
$token = SecurityToken::inst(); |
| 320 |
|
if (empty($vars[$token->getName()]) || !$token->check($vars[$token->getName()])) { |
| 321 |
|
return new HTTPResponse(null, 400); |
| 322 |
|
} |
| 323 |
|
|
| 324 |
|
if (!isset($vars['ids']) || !$vars['ids']) { |
| 325 |
|
return (new HTTPResponse(json_encode(['status' => 'error']), 400)) |
|
@@ 366-368 (lines=3) @@
|
| 363 |
|
|
| 364 |
|
// CSRF check |
| 365 |
|
$token = SecurityToken::inst(); |
| 366 |
|
if (empty($data[$token->getName()]) || !$token->check($data[$token->getName()])) { |
| 367 |
|
return new HTTPResponse(null, 400); |
| 368 |
|
} |
| 369 |
|
|
| 370 |
|
// Check parent record |
| 371 |
|
/** @var Folder $parentRecord */ |
|
@@ 542-544 (lines=3) @@
|
| 539 |
|
|
| 540 |
|
// CSRF check |
| 541 |
|
$token = SecurityToken::inst(); |
| 542 |
|
if (empty($data[$token->getName()]) || !$token->check($data[$token->getName()])) { |
| 543 |
|
return new HTTPResponse(null, 400); |
| 544 |
|
} |
| 545 |
|
|
| 546 |
|
// check addchildren permissions |
| 547 |
|
/** @var Folder $parentRecord */ |