'movefolder' requires a formtoken

This commit is contained in:
Uwe Steinmann 2014-06-04 19:17:08 +02:00
parent c09e650c89
commit e0a49734f0

View File

@ -182,6 +182,10 @@ switch($command) {
case 'movefolder': /* {{{ */
if($user) {
if(!checkFormKey('movefolder', 'GET')) {
header('Content-Type', 'application/json');
echo json_encode(array('success'=>false, 'message'=>getMLText('invalid_request_token'), 'data'=>''));
} else {
$mfolder = $dms->getFolder($_REQUEST['folderid']);
if($mfolder) {
if ($mfolder->getAccessMode($user) >= M_READ) {
@ -211,6 +215,7 @@ switch($command) {
echo json_encode(array('success'=>false, 'message'=>'No folder', 'data'=>''));
}
}
}
break; /* }}} */
case 'movedocument': /* {{{ */