This commit is contained in:
Ad Schellevis 2017-01-20 11:05:08 +01:00
parent 9eeca3405b
commit f5ef237970
2 changed files with 2 additions and 4 deletions

View File

@ -175,9 +175,8 @@ class ApiControllerBase extends ControllerRoot
}
// check for valid csrf on post requests
$csrf_tokenkey = $this->request->getHeader('X_CSRFTOKENKEY');
$csrf_token = $this->request->getHeader('X_CSRFTOKEN');
$csrf_valid = $this->security->checkToken($csrf_tokenkey, $csrf_token, false);
$csrf_token = $this->request->getHeader('X_CSRFTOKEN');
$csrf_valid = $this->security->checkToken(null, $csrf_token, false);
if (($this->request->isPost() ||
$this->request->isPut() ||

View File

@ -51,7 +51,6 @@
$.ajaxSetup({
'beforeSend': function(xhr) {
xhr.setRequestHeader("X-CSRFToken", "{{ csrf_token }}" );
xhr.setRequestHeader("X-CSRFTokenKey", "{{ csrf_tokenKey }}" );
}
});
// propagate ajax error messages