🔒 Add CSRF protection for import and import_items.

This commit is contained in:
Klaus Weidenbach
2017-03-29 23:53:03 +02:00
parent dea4879938
commit 81736a0129
4 changed files with 8 additions and 7 deletions

View File

@@ -15,6 +15,8 @@ class Import_items extends \Zotlabs\Web\Controller {
if(! local_channel())
return;
check_form_security_token_redirectOnErr('/import_items', 'import_items');
$data = null;
$src = $_FILES['filename']['tmp_name'];
@@ -123,6 +125,7 @@ class Import_items extends \Zotlabs\Web\Controller {
'$title' => t('Import Items'),
'$desc' => t('Use this form to import existing posts and content from an export file.'),
'$label_filename' => t('File to Upload'),
'$form_security_token' => get_form_security_token('import_items'),
'$submit' => t('Submit')
));