mirror of
https://github.com/myvesta/vesta
synced 2025-08-20 21:34:12 -07:00
Preventing CSRF in /schedule/backup
This commit is contained in:
parent
92297f2fc2
commit
9277b37800
1 changed files with 1 additions and 9 deletions
|
@ -1,15 +1,7 @@
|
||||||
<?php
|
<?php
|
||||||
|
|
||||||
// Preventing CSRF
|
// Preventing CSRF
|
||||||
if ($_SERVER['REQUEST_METHOD']=='POST') {
|
prevent_post_csrf(true);
|
||||||
$host_arr=explode(":", $_SERVER['HTTP_HOST']);
|
|
||||||
$hostname=$host_arr[0];
|
|
||||||
$port = $_SERVER['SERVER_PORT'];
|
|
||||||
$expected_http_origin="https://".$hostname.":".$port;
|
|
||||||
if ($_SERVER['HTTP_ORIGIN'] != $expected_http_origin) {
|
|
||||||
die ("Nope.");
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
// Init
|
// Init
|
||||||
error_reporting(NULL);
|
error_reporting(NULL);
|
||||||
|
|
Loading…
Add table
Add a link
Reference in a new issue