Controller: Add CSRF token validation to development toggle
This commit is contained in:
@@ -21,6 +21,7 @@ class CacheController extends PageController {
|
||||
$this->router->service()->config = $config;
|
||||
$this->router->service()->csrfToken = Session::token();
|
||||
$this->router->service()->purgeUrl = $this->url . '/purge';
|
||||
$this->router->service()->toggleUrl = $this->url . '/toggle';
|
||||
parent::view();
|
||||
}
|
||||
|
||||
@@ -81,7 +82,7 @@ class CacheController extends PageController {
|
||||
|
||||
public function toggleAction(): void
|
||||
{
|
||||
if (Config::c('CLOUDFLARE_ENABLED') != '1') {
|
||||
if (!$this->validatePostRequest()) {
|
||||
return;
|
||||
}
|
||||
|
||||
|
||||
@@ -75,6 +75,7 @@ use \App\Classes\Config;
|
||||
<div class="col-3 col-md-2 col-lg-2 col-xl-2">
|
||||
<div class="d-flex justify-content-center">
|
||||
<input type="checkbox" id="development-mode"
|
||||
data-href="<?= $this->toggleUrl; ?>" data-token="<?= $this->csrfToken; ?>"
|
||||
<?= $this->config['CLOUDFLARE_DEVELOPMENT_MODE_ENABLED'] ? 'checked' : ''; ?>>
|
||||
</div>
|
||||
</div>
|
||||
|
||||
Reference in New Issue
Block a user