Controller: Add CSRF token validation to development toggle

This commit is contained in:
Riyyi
2021-08-30 01:02:50 +02:00
parent d50443b10a
commit 9a99c31d47
3 changed files with 37 additions and 22 deletions
+34 -21
View File
@@ -233,13 +233,13 @@ $(document).ready(function() {
{
event.preventDefault();
const purgeType = $(this).attr('data-type');
const csrfToken = $(this).attr('data-token');
if (!confirm('Are you sure you want to continue?')) {
return;
}
const purgeType = $(this).attr('data-type');
const csrfToken = $(this).attr('data-token');
$.ajax({
url: $(this).attr('href'),
type: 'POST',
@@ -272,26 +272,39 @@ $(document).ready(function() {
return;
}
$.get('/admin/cache/toggle').done(function(data)
{
const response = JSON.parse(data);
if (response.success == false) {
console.log(data);
alert("Development mode could not be enabled!");
return;
}
const dataHref = $(this).attr('data-href');
const csrfToken = $(this).attr('data-token');
if (response.result.value == 'on') {
e.target.checked = true;
$('#develop-enabled').css('visibility', 'visible');
$('#develop-remaining').text('03:00:00');
}
else {
e.target.checked = false;
$('#develop-enabled').css('visibility', 'hidden');
}
$.ajax({
url: dataHref,
type: 'POST',
data: { _token: csrfToken },
success: function(data)
{
if (data == '') {
alert("Development mode could not be enabled!");
return;
}
alert("Development mode has been set to: '" + response.result.value + "'");
const response = JSON.parse(data);
if (response.success == false) {
console.log(data);
alert("Development mode could not be enabled!");
return;
}
if (response.result.value == 'on') {
e.target.checked = true;
$('#develop-enabled').css('visibility', 'visible');
$('#develop-remaining').text('03:00:00');
}
else {
e.target.checked = false;
$('#develop-enabled').css('visibility', 'hidden');
}
alert("Development mode has been set to: '" + response.result.value + "'");
}
});
});