All fetch() POSTs now send application/x-www-form-urlencoded with the page-injected csrf_token, satisfying unRAID's auto_prepend CSRF check. All PHP API handlers switched from php://input JSON to $_POST. Also adds Dry Run button (orange, between Run and Log) that sets DRY_RUN=1 in the script environment before executing.
84 lines
3.2 KiB
PHP
84 lines
3.2 KiB
PHP
<?php
|
|
require_once dirname(__DIR__) . '/include/config.php';
|
|
$files = vv_get_conf_files();
|
|
$active = $_GET['conf'] ?? ($files[0] ?? '');
|
|
if (!in_array($active, $files)) $active = $files[0] ?? '';
|
|
$currentScriptsDir = SCRIPTS_DIR;
|
|
?>
|
|
|
|
<div id="vv-config">
|
|
|
|
<!-- Plugin Settings -->
|
|
<div class="vv-card vv-wide" style="margin-bottom:16px;">
|
|
<h3>Plugin Settings</h3>
|
|
<div class="vv-job-row" style="max-width:700px;gap:8px;">
|
|
<label style="color:#aaa;font-size:13px;white-space:nowrap;">Scripts directory</label>
|
|
<input type="text" id="vv-scripts-dir" value="<?= htmlspecialchars($currentScriptsDir) ?>"
|
|
style="flex:1;background:#111;border:1px solid #444;color:#ddd;padding:4px 8px;
|
|
border-radius:4px;font-family:monospace;font-size:13px;">
|
|
<button type="button" onclick="vvSaveSettings()" style="padding:4px 14px;background:#4caf50;
|
|
border:none;color:#fff;border-radius:4px;cursor:pointer;font-size:13px;">Save</button>
|
|
<span id="vv-settings-status" style="font-size:13px;color:#aaa;"></span>
|
|
</div>
|
|
</div>
|
|
|
|
<!-- File selector -->
|
|
<div id="vv-conf-tabs">
|
|
<?php foreach ($files as $f): ?>
|
|
<a href="?tab=config&conf=<?= urlencode($f) ?>"
|
|
class="vv-conf-tab<?= $f === $active ? ' active' : '' ?>">
|
|
<?= htmlspecialchars($f) ?>
|
|
</a>
|
|
<?php endforeach; ?>
|
|
</div>
|
|
|
|
<?php if ($active): ?>
|
|
<form id="vv-conf-form">
|
|
<input type="hidden" name="file" value="<?= htmlspecialchars($active) ?>">
|
|
<textarea id="vv-conf-editor" name="content" spellcheck="false"><?=
|
|
htmlspecialchars(vv_read_conf_raw($active))
|
|
?></textarea>
|
|
<div id="vv-conf-actions">
|
|
<button type="button" onclick="vvSaveConf()">Save</button>
|
|
<span id="vv-conf-status"></span>
|
|
</div>
|
|
</form>
|
|
<?php else: ?>
|
|
<p>No configuration files found.</p>
|
|
<?php endif; ?>
|
|
|
|
</div>
|
|
|
|
<script>
|
|
function vvPost(url, data) {
|
|
const params = new URLSearchParams({csrf_token, ...data});
|
|
return fetch(url, {
|
|
method: 'POST',
|
|
headers: {'Content-Type': 'application/x-www-form-urlencoded'},
|
|
body: params
|
|
}).then(r => r.json());
|
|
}
|
|
|
|
function vvSaveSettings() {
|
|
const dir = document.getElementById('vv-scripts-dir').value.trim();
|
|
const status = document.getElementById('vv-settings-status');
|
|
if (!dir) { status.textContent = '✗ Path required'; return; }
|
|
status.textContent = 'Saving...';
|
|
vvPost('/plugins/varaverk/api/settings.php', {scripts_dir: dir})
|
|
.then(d => { status.textContent = d.ok ? '✓ Saved — reload to apply' : '✗ ' + (d.error ?? 'Error'); })
|
|
.catch(() => { status.textContent = '✗ Request failed'; });
|
|
}
|
|
|
|
function vvSaveConf() {
|
|
const form = document.getElementById('vv-conf-form');
|
|
const file = form.querySelector('[name=file]').value;
|
|
const content = form.querySelector('[name=content]').value;
|
|
const status = document.getElementById('vv-conf-status');
|
|
|
|
status.textContent = 'Saving...';
|
|
vvPost('/plugins/varaverk/api/config.php', {file, content})
|
|
.then(d => { status.textContent = d.ok ? '✓ Saved' : '✗ ' + (d.error ?? 'Error'); })
|
|
.catch(() => { status.textContent = '✗ Request failed'; });
|
|
}
|
|
</script>
|