mirror of
https://github.com/itflow-org/itflow
synced 2026-03-11 00:04:50 +00:00
Add CSRF Checks on Agent ajax endpoints that would update / delete or add something to the db
This commit is contained in:
@@ -148,6 +148,7 @@ new Sortable(document.querySelector('table#tasks tbody'), {
|
||||
|
||||
$.post('/agent/ajax.php', {
|
||||
update_task_templates_order: true,
|
||||
csrf_token: '<?= $_SESSION['csrf_token'] ?>',
|
||||
ticket_template_id: <?php echo $ticket_template_id; ?>,
|
||||
positions: positions
|
||||
});
|
||||
|
||||
Reference in New Issue
Block a user