diff --git a/Admin/Routes/Web/Api.php b/Admin/Routes/Web/Api.php index 8c3f9ac..3dc8f06 100755 --- a/Admin/Routes/Web/Api.php +++ b/Admin/Routes/Web/Api.php @@ -22,6 +22,7 @@ return [ [ 'dest' => '\Modules\Editor\Controller\ApiController:apiEditorCreate', 'verb' => RouteVerb::PUT, + 'csrf' => true, 'permission' => [ 'module' => ApiController::NAME, 'type' => PermissionType::CREATE, @@ -31,6 +32,7 @@ return [ [ 'dest' => '\Modules\Editor\Controller\ApiController:apiEditorUpdate', 'verb' => RouteVerb::SET, + 'csrf' => true, 'permission' => [ 'module' => ApiController::NAME, 'type' => PermissionType::MODIFY, @@ -40,6 +42,7 @@ return [ [ 'dest' => '\Modules\Editor\Controller\ApiController:apiEditorGet', 'verb' => RouteVerb::GET, + 'csrf' => true, 'permission' => [ 'module' => ApiController::NAME, 'type' => PermissionType::READ, @@ -49,6 +52,7 @@ return [ [ 'dest' => '\Modules\Editor\Controller\ApiController:apiEditorDelete', 'verb' => RouteVerb::DELETE, + 'csrf' => true, 'permission' => [ 'module' => ApiController::NAME, 'type' => PermissionType::DELETE, @@ -60,6 +64,7 @@ return [ [ 'dest' => '\Modules\Editor\Controller\ApiController:apiDocExport', 'verb' => RouteVerb::GET, + 'csrf' => true, 'permission' => [ 'module' => ApiController::NAME, 'type' => PermissionType::READ, diff --git a/Theme/Backend/Components/Compound/compound.tpl.php b/Theme/Backend/Components/Compound/compound.tpl.php index 8a07b8a..d8ed6aa 100644 --- a/Theme/Backend/Components/Compound/compound.tpl.php +++ b/Theme/Backend/Components/Compound/compound.tpl.php @@ -40,7 +40,7 @@ docs as $doc) : ?>