summaryrefslogtreecommitdiffstats
path: root/settings/ajax/createuser.php
diff options
context:
space:
mode:
authorLukas Reschke <lukas@statuscode.ch>2012-07-07 15:27:04 +0200
committerLukas Reschke <lukas@statuscode.ch>2012-07-07 15:27:04 +0200
commit777eb1d8b1d68f93d986bf2c8280e7416a1694e6 (patch)
tree75736860128c6d7cb6ef8ca628e039af71f55c15 /settings/ajax/createuser.php
parentec7bb86b2875c9e5afbd7db57de3c872afc3e90b (diff)
downloadnextcloud-server-777eb1d8b1d68f93d986bf2c8280e7416a1694e6.tar.gz
nextcloud-server-777eb1d8b1d68f93d986bf2c8280e7416a1694e6.zip
CSRF check in the settings
Diffstat (limited to 'settings/ajax/createuser.php')
-rw-r--r--settings/ajax/createuser.php1
1 files changed, 1 insertions, 0 deletions
diff --git a/settings/ajax/createuser.php b/settings/ajax/createuser.php
index 6714711bc87..079b4750b7d 100644
--- a/settings/ajax/createuser.php
+++ b/settings/ajax/createuser.php
@@ -8,6 +8,7 @@ if( !OC_User::isLoggedIn() || !OC_Group::inGroup( OC_User::getUser(), 'admin' ))
OC_JSON::error(array("data" => array( "message" => "Authentication error" )));
exit();
}
+OCP\JSON::callCheck();
$groups = array();
if( isset( $_POST["groups"] )){