Add Dry Run button; fix CSRF token on all POST API calls

All fetch() POSTs now send application/x-www-form-urlencoded with the
page-injected csrf_token, satisfying unRAID's auto_prepend CSRF check.
All PHP API handlers switched from php://input JSON to $_POST.

Also adds Dry Run button (orange, between Run and Log) that sets
DRY_RUN=1 in the script environment before executing.
This commit is contained in:
Gmer4Lfe
2026-05-23 17:50:47 -04:00
parent 131d9093b0
commit d0b842a489
9 changed files with 98 additions and 63 deletions
@@ -2,10 +2,9 @@
header('Content-Type: application/json');
require_once dirname(__DIR__) . '/include/scheduler.php';
$body = json_decode(file_get_contents('php://input'), true);
$id = trim($body['id'] ?? '');
$enabled = (bool)($body['enabled'] ?? false);
$cron = trim($body['cron'] ?? '');
$id = trim($_POST['id'] ?? '');
$enabled = (bool)($_POST['enabled'] ?? false);
$cron = trim($_POST['cron'] ?? '');
if (!$id) {
echo json_encode(['ok' => false, 'error' => 'Missing id']);