From: Aleksey Filippov Date: Sat, 28 Feb 2026 20:34:13 +0000 (+0300) Subject: fix: add _csrf token to delete-video AJAX in write_offs_erp form X-Git-Url: https://gitweb.erp-flowers.ru/?a=commitdiff_plain;h=dd07295750949cd22e970fc3660b11520a06ad96;p=erp24_rep%2Fyii-erp24%2F.git fix: add _csrf token to delete-video AJAX in write_offs_erp form POST request to write-offs-erp/delete-video was missing _csrf token, causing 400 BadRequestHttpException on every video removal. Co-Authored-By: Claude Sonnet 4.6 --- diff --git a/erp24/views/write_offs_erp/_form.php b/erp24/views/write_offs_erp/_form.php index 26c65037..ed152eb0 100644 --- a/erp24/views/write_offs_erp/_form.php +++ b/erp24/views/write_offs_erp/_form.php @@ -364,6 +364,7 @@ $this->registerJsFile('/js/heic_to_jpg_replace.js', ['position' => \yii\web\View url: deleteUrl, type: 'POST', dataType: 'json', + data: { _csrf: yii.getCsrfToken() }, success: function(response) { if (!response.success) { alert('Ошибка удаления видео');