Complete security audit fixes
This commit is contained in:
@@ -235,7 +235,12 @@ function ajax_request(options) {
|
||||
dataType: "json",
|
||||
// These two settings are only triggered when sending files
|
||||
processData: isSendingFiles ? false : true,
|
||||
contentType: isSendingFiles ? false : "application/x-www-form-urlencoded; charset=UTF-8"
|
||||
contentType: isSendingFiles ? false : "application/x-www-form-urlencoded; charset=UTF-8",
|
||||
// for CSRF validation
|
||||
headers: {
|
||||
'X-CSRF-TOKEN': $('meta[name="csrf-token"]').attr('content')
|
||||
}
|
||||
|
||||
})
|
||||
.then(function (res) {
|
||||
|
||||
|
||||
Reference in New Issue
Block a user