summaryrefslogtreecommitdiffstats
path: root/settings/ajax/creategroup.php
diff options
context:
space:
mode:
authorLukas Reschke <lukas@statuscode.ch>2012-07-07 15:27:04 +0200
committerLukas Reschke <lukas@statuscode.ch>2012-07-07 15:27:04 +0200
commit777eb1d8b1d68f93d986bf2c8280e7416a1694e6 (patch)
tree75736860128c6d7cb6ef8ca628e039af71f55c15 /settings/ajax/creategroup.php
parentec7bb86b2875c9e5afbd7db57de3c872afc3e90b (diff)
downloadnextcloud-server-777eb1d8b1d68f93d986bf2c8280e7416a1694e6.tar.gz
nextcloud-server-777eb1d8b1d68f93d986bf2c8280e7416a1694e6.zip
CSRF check in the settings
Diffstat (limited to 'settings/ajax/creategroup.php')
-rw-r--r--settings/ajax/creategroup.php2
1 files changed, 2 insertions, 0 deletions
diff --git a/settings/ajax/creategroup.php b/settings/ajax/creategroup.php
index 57d82e7bd94..3626600ad9b 100644
--- a/settings/ajax/creategroup.php
+++ b/settings/ajax/creategroup.php
@@ -9,6 +9,8 @@ if( !OC_User::isLoggedIn() || !OC_Group::inGroup( OC_User::getUser(), 'admin' ))
exit();
}
+OCP\JSON::callCheck();
+
$groupname = $_POST["groupname"];
// Does the group exist?