Files
Varaverk/Plugin/usr/local/emhttp/plugins/varaverk/api/config.php
T
Gmer4Lfe d0b842a489 Add Dry Run button; fix CSRF token on all POST API calls
All fetch() POSTs now send application/x-www-form-urlencoded with the
page-injected csrf_token, satisfying unRAID's auto_prepend CSRF check.
All PHP API handlers switched from php://input JSON to $_POST.

Also adds Dry Run button (orange, between Run and Log) that sets
DRY_RUN=1 in the script environment before executing.
2026-05-23 17:50:47 -04:00

17 lines
508 B
PHP

<?php
header('Content-Type: application/json');
require_once dirname(__DIR__) . '/include/config.php';
$file = trim($_POST['file'] ?? '');
$content = $_POST['content'] ?? '';
// Must be an allowed file for this host
$allowed = vv_get_conf_files();
if (!$file || !in_array($file, $allowed)) {
echo json_encode(['ok' => false, 'error' => 'File not permitted']);
exit;
}
$ok = vv_write_conf_raw($file, $content);
echo json_encode(['ok' => $ok, 'error' => $ok ? null : 'Failed to write file']);