diff --git a/Admin/Routes/Web/Api.php b/Admin/Routes/Web/Api.php index 3ffbde0..f6ab449 100755 --- a/Admin/Routes/Web/Api.php +++ b/Admin/Routes/Web/Api.php @@ -24,6 +24,7 @@ return [ [ 'dest' => '\Modules\Profile\Controller\ApiController:apiProfileCreate', 'verb' => RouteVerb::PUT, + 'csrf' => true, 'permission' => [ 'module' => ApiController::NAME, 'type' => PermissionType::CREATE, @@ -36,6 +37,7 @@ return [ [ 'dest' => '\Modules\Admin\Controller\ApiController:apiSettingsAccountLocalizationSet', 'verb' => RouteVerb::SET, + 'csrf' => true, 'permission' => [ 'module' => AdminApiController::NAME, 'type' => PermissionType::MODIFY, @@ -47,6 +49,7 @@ return [ [ 'dest' => '\Modules\Admin\Controller\ApiController:apiSettingsAccountPasswordSet', 'verb' => RouteVerb::SET, + 'csrf' => true, 'permission' => [ 'module' => AdminApiController::NAME, 'type' => PermissionType::MODIFY, @@ -58,6 +61,7 @@ return [ [ 'dest' => '\Modules\Profile\Controller\ApiController:apiSettingsAccountImageSet', 'verb' => RouteVerb::SET, + 'csrf' => true, 'permission' => [ 'module' => ApiController::NAME, 'type' => PermissionType::MODIFY, diff --git a/Admin/Routes/Web/Backend.php b/Admin/Routes/Web/Backend.php index 003cd6b..0d3dd75 100755 --- a/Admin/Routes/Web/Backend.php +++ b/Admin/Routes/Web/Backend.php @@ -57,7 +57,7 @@ return [ 'verb' => RouteVerb::GET, 'permission' => [ 'module' => BackendController::NAME, - 'type' => PermissionType::READ, + 'type' => PermissionType::CREATE, 'state' => PermissionCategory::PROFILE, ], ], diff --git a/Theme/Backend/Components/AccountGroupSelector/base.tpl.php b/Theme/Backend/Components/AccountGroupSelector/base.tpl.php index 3cfcfe4..0f9b4f7 100755 --- a/Theme/Backend/Components/AccountGroupSelector/base.tpl.php +++ b/Theme/Backend/Components/AccountGroupSelector/base.tpl.php @@ -14,7 +14,7 @@ } ]' formaction="">book