diff options
author | Frédéric Guillot <fred@kanboard.net> | 2018-01-29 15:56:30 -0800 |
---|---|---|
committer | Frédéric Guillot <fred@kanboard.net> | 2018-01-29 15:56:30 -0800 |
commit | 9ddefa979a12aff2334d6e7048e142cfdef5bb89 (patch) | |
tree | 30416f103ba88c7bdf1039c9d40085a7a784ddc0 /app/Template | |
parent | 90984d6bb9b3bd508e0ca7f8c0ee07d304679fb5 (diff) |
Add CSRF check for task and project files upload
Diffstat (limited to 'app/Template')
-rw-r--r-- | app/Template/project_file/create.php | 1 | ||||
-rw-r--r-- | app/Template/task_file/create.php | 1 |
2 files changed, 2 insertions, 0 deletions
diff --git a/app/Template/project_file/create.php b/app/Template/project_file/create.php index de35f87c..74c5fa70 100644 --- a/app/Template/project_file/create.php +++ b/app/Template/project_file/create.php @@ -3,6 +3,7 @@ </div> <?= $this->app->component('file-upload', array( + 'csrf' => $this->app->getToken()->getReusableCSRFToken(), 'maxSize' => $max_size, 'url' => $this->url->to('ProjectFileController', 'save', array('project_id' => $project['id'])), 'labelDropzone' => t('Drag and drop your files here'), diff --git a/app/Template/task_file/create.php b/app/Template/task_file/create.php index eebb08eb..46fc7d66 100644 --- a/app/Template/task_file/create.php +++ b/app/Template/task_file/create.php @@ -3,6 +3,7 @@ </div> <?= $this->app->component('file-upload', array( + 'csrf' => $this->app->getToken()->getReusableCSRFToken(), 'maxSize' => $max_size, 'url' => $this->url->to('TaskFileController', 'save', array('task_id' => $task['id'], 'project_id' => $task['project_id'])), 'labelDropzone' => t('Drag and drop your files here'), |