From 9ddefa979a12aff2334d6e7048e142cfdef5bb89 Mon Sep 17 00:00:00 2001 From: Frédéric Guillot Date: Mon, 29 Jan 2018 15:56:30 -0800 Subject: Add CSRF check for task and project files upload --- app/Template/task_file/create.php | 1 + 1 file changed, 1 insertion(+) (limited to 'app/Template/task_file') diff --git a/app/Template/task_file/create.php b/app/Template/task_file/create.php index eebb08eb..46fc7d66 100644 --- a/app/Template/task_file/create.php +++ b/app/Template/task_file/create.php @@ -3,6 +3,7 @@ app->component('file-upload', array( + 'csrf' => $this->app->getToken()->getReusableCSRFToken(), 'maxSize' => $max_size, 'url' => $this->url->to('TaskFileController', 'save', array('task_id' => $task['id'], 'project_id' => $task['project_id'])), 'labelDropzone' => t('Drag and drop your files here'), -- cgit v1.2.3