diff options
| author | Bharat Mediratta <bharat@menalto.com> | 2009-03-27 03:43:21 +0000 |
|---|---|---|
| committer | Bharat Mediratta <bharat@menalto.com> | 2009-03-27 03:43:21 +0000 |
| commit | 921f3a2eeeca9be23cb006a31b6d6f71e186374a (patch) | |
| tree | f9626ae5191418410714b662799649de5a1ea37c /core/views/permissions_browse.html.php | |
| parent | d7719a7e72de2ddc46c9173b0871f53e32ef40fc (diff) | |
Put csrf token into Admin_View and Theme_View by default, then use it
directly wherever possible instead of access::csrf_token().
Diffstat (limited to 'core/views/permissions_browse.html.php')
| -rw-r--r-- | core/views/permissions_browse.html.php | 2 |
1 files changed, 1 insertions, 1 deletions
diff --git a/core/views/permissions_browse.html.php b/core/views/permissions_browse.html.php index 4c960134..36d097cc 100644 --- a/core/views/permissions_browse.html.php +++ b/core/views/permissions_browse.html.php @@ -12,7 +12,7 @@ }); } - var action_url = "<?= url::site("permissions/change/__CMD__/__GROUP__/__PERM__/__ITEM__?csrf=" . access::csrf_token()) ?>"; + var action_url = "<?= url::site("permissions/change/__CMD__/__GROUP__/__PERM__/__ITEM__?csrf=$csrf") ?>"; set = function(cmd, group_id, perm_id, item_id) { $.ajax({ url: action_url.replace("__CMD__", cmd).replace("__GROUP__", group_id). |
