mirror of
https://github.com/itflow-org/itflow
synced 2026-03-11 16:24:50 +00:00
Add CSRF Checks on Agent ajax endpoints that would update / delete or add something to the db
This commit is contained in:
@@ -817,6 +817,7 @@ new Sortable(document.querySelector('table#items tbody'), {
|
||||
|
||||
$.post('ajax.php', {
|
||||
update_invoice_items_order: true,
|
||||
csrf_token: '<?= $_SESSION['csrf_token'] ?>',
|
||||
invoice_id: <?php echo $invoice_id; ?>,
|
||||
positions: positions
|
||||
});
|
||||
|
||||
Reference in New Issue
Block a user