Budget - CSRF + Perms

This commit is contained in:
wrongecho
2024-10-03 20:52:37 +01:00
parent 6d6689e7c5
commit f8c6a5ef19
2 changed files with 14 additions and 0 deletions

View File

@@ -2,6 +2,8 @@
require_once "inc_all.php";
enforceUserPermission('module_financial', 2);
// Fetch categories
$query = "SELECT category_id, category_name FROM categories WHERE category_type ='Expense' AND category_archived_at IS NULL";
$result = mysqli_query($mysqli, $query);
@@ -52,6 +54,8 @@ $grandTotal = 0;
</form>
<form id="budgetForm" method="POST" action="post.php">
<input type="hidden" name="year" value="<?php echo $currentYear; ?>">
<input type="hidden" name="csrf_token" value="<?php echo $_SESSION['csrf_token'] ?>">
<table class="table table-bordered table-striped">
<thead>
<tr>