]> gitweb.erp-flowers.ru Git - erp24_rep/yii-erp24/.git/commitdiff
fix: add _csrf token to delete-video AJAX in write_offs_erp form origin/feature_filippov_fix_write_offs_erp_delete_video_csrf
authorAleksey Filippov <Aleksey.Filippov@erp-flowers.ru>
Sat, 28 Feb 2026 20:34:13 +0000 (23:34 +0300)
committerAleksey Filippov <Aleksey.Filippov@erp-flowers.ru>
Sat, 28 Feb 2026 20:34:13 +0000 (23:34 +0300)
POST request to write-offs-erp/delete-video was missing _csrf token,
causing 400 BadRequestHttpException on every video removal.

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
erp24/views/write_offs_erp/_form.php

index 26c65037aa4a85b3af6975d9cbaca1368571ece3..ed152eb066486526de87e920c8b98334fc872159 100644 (file)
@@ -364,6 +364,7 @@ $this->registerJsFile('/js/heic_to_jpg_replace.js', ['position' => \yii\web\View
                                             url: deleteUrl,
                                             type: 'POST',
                                             dataType: 'json',
+                                            data: { _csrf: yii.getCsrfToken() },
                                             success: function(response) {
                                                 if (!response.success) {
                                                     alert('Ошибка удаления видео');