From 311214ad7fa0077f9da900c7137c65f7cd4e78b0 Mon Sep 17 00:00:00 2001 From: Alice Gaudon Date: Sat, 11 Jul 2020 12:17:03 +0200 Subject: [PATCH 1/2] Fix missing csrf field in file manager delete form --- src/controllers/FileController.ts | 2 +- views/file-manager.njk | 1 + 2 files changed, 2 insertions(+), 1 deletion(-) diff --git a/src/controllers/FileController.ts b/src/controllers/FileController.ts index 7a0ff66..8bb1e00 100644 --- a/src/controllers/FileController.ts +++ b/src/controllers/FileController.ts @@ -97,7 +97,7 @@ export default class FileController extends Controller { switch (file.storage_type) { case 'local': - await this.deleteFile(file); + await FileController.deleteFile(file); break; default: throw new ServerError(`This file cannot be deleted. Deletion protocol for ${file.storage_type} storage type not implemented.`); diff --git a/views/file-manager.njk b/views/file-manager.njk index 29927ed..5376b9c 100644 --- a/views/file-manager.njk +++ b/views/file-manager.njk @@ -43,6 +43,7 @@ Pending deletion {% else %}
+ {{ macros.csrf(getCSRFToken) }}
{% endif %} From 7d0cb5f1a01904e077cb0d69e0fc8812d2827382 Mon Sep 17 00:00:00 2001 From: Alice Gaudon Date: Sat, 11 Jul 2020 12:17:39 +0200 Subject: [PATCH 2/2] Version 0.4.4 --- package.json | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/package.json b/package.json index 65ed368..cc5a78b 100644 --- a/package.json +++ b/package.json @@ -1,6 +1,6 @@ { "name": "ily.li", - "version": "0.4.3", + "version": "0.4.4", "description": "Self-hosted file pusher", "repository": "git@gitlab.com:ArisuOngaku/ily.li.git", "author": "Alice Gaudon ",