mirror of
https://github.com/billz/raspap-webgui.git
synced 2025-03-01 10:31:47 +00:00
send CSRF token in a response header,
update the page's CSRF tokens with the new token from the response header, verify csrf token in ajax endpoints, initialize a session for every endpoint
This commit is contained in:
@@ -1,8 +1,10 @@
|
||||
<?php
|
||||
|
||||
require('includes/csrf.php');
|
||||
|
||||
require_once '../../includes/config.php';
|
||||
require_once RASPI_CONFIG.'/raspap.php';
|
||||
|
||||
session_start();
|
||||
header('X-Frame-Options: DENY');
|
||||
header("Content-Security-Policy: default-src 'none'; connect-src 'self'");
|
||||
require_once '../../includes/authenticate.php';
|
||||
|
@@ -1,4 +1,7 @@
|
||||
<?php
|
||||
|
||||
require('includes/csrf.php');
|
||||
|
||||
if (filter_input(INPUT_GET, 'tu') == 'h') {
|
||||
|
||||
header('X-Content-Type-Options: nosniff');
|
||||
|
@@ -1,5 +1,7 @@
|
||||
<?php
|
||||
session_start();
|
||||
|
||||
require('includes/csrf.php');
|
||||
|
||||
include_once('../../includes/config.php');
|
||||
include_once('../../includes/functions.php');
|
||||
|
||||
|
@@ -1,4 +1,7 @@
|
||||
<?php
|
||||
|
||||
require('includes/csrf.php');
|
||||
|
||||
exec("ls /sys/class/net | grep -v lo", $interfaces);
|
||||
echo json_encode($interfaces);
|
||||
?>
|
||||
|
@@ -1,5 +1,7 @@
|
||||
<?php
|
||||
session_start();
|
||||
|
||||
require('includes/csrf.php');
|
||||
|
||||
include_once('../../includes/config.php');
|
||||
include_once('../../includes/functions.php');
|
||||
|
||||
|
@@ -1,5 +1,7 @@
|
||||
<?php
|
||||
session_start();
|
||||
|
||||
require('includes/csrf.php');
|
||||
|
||||
include_once('../../includes/functions.php');
|
||||
|
||||
if(isset($_POST['interface'])) {
|
||||
|
@@ -1,5 +1,7 @@
|
||||
<?php
|
||||
session_start();
|
||||
|
||||
require('includes/csrf.php');
|
||||
|
||||
include_once('../../includes/config.php');
|
||||
include_once('../../includes/functions.php');
|
||||
if(isset($_POST['interface'])) {
|
||||
|
Reference in New Issue
Block a user