Welcome to mirror list, hosted at ThFree Co, Russian Federation.

github.com/nextcloud/mail.git - Unnamed repository; edit this file 'description' to name the repository.
summaryrefslogtreecommitdiff
diff options
context:
space:
mode:
authorChristoph Wurst <christoph@winzerhof-wurst.at>2017-09-12 15:30:04 +0300
committerChristoph Wurst <christoph@winzerhof-wurst.at>2017-09-12 15:30:04 +0300
commitdafa968c1f791f9453492f47cd314c540f2f779f (patch)
treef433b683d4eb5bea6adc65625a18284e24cb4d30 /lib/Controller
parent29bc371e5bac036fb009e6707cd697afd56cd8b3 (diff)
Add more csrf checks
Signed-off-by: Christoph Wurst <christoph@winzerhof-wurst.at>
Diffstat (limited to 'lib/Controller')
-rw-r--r--lib/Controller/AccountsController.php1
-rw-r--r--lib/Controller/AliasesController.php5
-rw-r--r--lib/Controller/FoldersController.php3
-rwxr-xr-xlib/Controller/MessagesController.php2
4 files changed, 0 insertions, 11 deletions
diff --git a/lib/Controller/AccountsController.php b/lib/Controller/AccountsController.php
index 81308b957..13b9710bd 100644
--- a/lib/Controller/AccountsController.php
+++ b/lib/Controller/AccountsController.php
@@ -100,7 +100,6 @@ class AccountsController extends Controller {
/**
* @NoAdminRequired
- * @NoCSRFRequired
*
* @return JSONResponse
*/
diff --git a/lib/Controller/AliasesController.php b/lib/Controller/AliasesController.php
index 7ce23850e..5a7208ba7 100644
--- a/lib/Controller/AliasesController.php
+++ b/lib/Controller/AliasesController.php
@@ -51,7 +51,6 @@ class AliasesController extends Controller {
/**
* @NoAdminRequired
- * @NoCSRFRequired
* @param int $accountId
* @return Alias[]
*/
@@ -61,7 +60,6 @@ class AliasesController extends Controller {
/**
* @NoAdminRequired
- * @NoCSRFRequired
*/
public function show() {
$response = new JSONResponse();
@@ -71,7 +69,6 @@ class AliasesController extends Controller {
/**
* @NoAdminRequired
- * @NoCSRFRequired
*/
public function update() {
$response = new JSONResponse();
@@ -81,7 +78,6 @@ class AliasesController extends Controller {
/**
* @NoAdminRequired
- * @NoCSRFRequired
* @param int $id
* @return Alias[]
*/
@@ -91,7 +87,6 @@ class AliasesController extends Controller {
/**
* @NoAdminRequired
- * @NoCSRFRequired
* @param int $accountId
* @param string $alias
* @param string $aliasName
diff --git a/lib/Controller/FoldersController.php b/lib/Controller/FoldersController.php
index e5dd439d2..6bd1fd7f4 100644
--- a/lib/Controller/FoldersController.php
+++ b/lib/Controller/FoldersController.php
@@ -62,7 +62,6 @@ class FoldersController extends Controller {
/**
* @NoAdminRequired
- * @NoCSRFRequired
* @param int $accountId
* @return JSONResponse
*/
@@ -80,7 +79,6 @@ class FoldersController extends Controller {
/**
* @NoAdminRequired
- * @NoCSRFRequired
* @param int $accountId
* @param string $folderId
* @param string $syncToken
@@ -99,7 +97,6 @@ class FoldersController extends Controller {
/**
* @NoAdminRequired
- * @NoCSRFRequired
*/
public function show() {
$response = new JSONResponse();
diff --git a/lib/Controller/MessagesController.php b/lib/Controller/MessagesController.php
index 6cbad6911..a52500ecf 100755
--- a/lib/Controller/MessagesController.php
+++ b/lib/Controller/MessagesController.php
@@ -115,7 +115,6 @@ class MessagesController extends Controller {
/**
* @NoAdminRequired
- * @NoCSRFRequired
*
* @param int $accountId
* @param string $folderId
@@ -295,7 +294,6 @@ class MessagesController extends Controller {
/**
* @NoAdminRequired
- * @NoCSRFRequired
*
* @param int $accountId
* @param string $folderId