Add missing CSRF check in TwoFactorController::deactivate()
This commit is contained in:
@@ -33,6 +33,13 @@ abstract class BaseController extends Base
|
|||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
|
protected function checkCSRFForm()
|
||||||
|
{
|
||||||
|
if (! $this->token->validateCSRFToken($this->request->getRawValue('csrf_token'))) {
|
||||||
|
throw new AccessForbiddenException();
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
/**
|
/**
|
||||||
* Check webhook token
|
* Check webhook token
|
||||||
*
|
*
|
||||||
|
|||||||
@@ -119,6 +119,7 @@ class TwoFactorController extends UserViewController
|
|||||||
*/
|
*/
|
||||||
public function deactivate()
|
public function deactivate()
|
||||||
{
|
{
|
||||||
|
$this->checkCSRFForm();
|
||||||
$user = $this->getUser();
|
$user = $this->getUser();
|
||||||
$this->checkCurrentUser($user);
|
$this->checkCurrentUser($user);
|
||||||
|
|
||||||
|
|||||||
Reference in New Issue
Block a user