All fetch() POSTs now send application/x-www-form-urlencoded with the page-injected csrf_token, satisfying unRAID's auto_prepend CSRF check. All PHP API handlers switched from php://input JSON to $_POST. Also adds Dry Run button (orange, between Run and Log) that sets DRY_RUN=1 in the script environment before executing.
24 lines
674 B
PHP
24 lines
674 B
PHP
<?php
|
|
header('Content-Type: application/json');
|
|
|
|
$scriptsDir = trim($_POST['scripts_dir'] ?? '');
|
|
|
|
if (!$scriptsDir) {
|
|
echo json_encode(['ok' => false, 'error' => 'scripts_dir is required']);
|
|
exit;
|
|
}
|
|
|
|
if (!is_dir($scriptsDir)) {
|
|
echo json_encode(['ok' => false, 'error' => 'Directory does not exist']);
|
|
exit;
|
|
}
|
|
|
|
$cfgFile = '/boot/config/plugins/varaverk/varaverk.cfg';
|
|
$cfgDir = dirname($cfgFile);
|
|
if (!is_dir($cfgDir)) mkdir($cfgDir, 0755, true);
|
|
|
|
$content = 'SCRIPTS_DIR="' . addslashes($scriptsDir) . '"' . "\n";
|
|
$ok = file_put_contents($cfgFile, $content) !== false;
|
|
|
|
echo json_encode(['ok' => $ok, 'error' => $ok ? null : 'Failed to write cfg file']);
|