diff --git a/api/assign_ticket.php b/api/assign_ticket.php index febc5f1..78ae531 100644 --- a/api/assign_ticket.php +++ b/api/assign_ticket.php @@ -12,6 +12,17 @@ if (!isset($_SESSION['user']) || !isset($_SESSION['user']['user_id'])) { exit; } +// CSRF Protection +require_once dirname(__DIR__) . '/middleware/CsrfMiddleware.php'; +if ($_SERVER['REQUEST_METHOD'] === 'POST') { + $csrfToken = $_SERVER['HTTP_X_CSRF_TOKEN'] ?? ''; + if (!CsrfMiddleware::validateToken($csrfToken)) { + http_response_code(403); + echo json_encode(['success' => false, 'error' => 'Invalid CSRF token']); + exit; + } +} + $userId = $_SESSION['user']['user_id']; // Get request data diff --git a/api/saved_filters.php b/api/saved_filters.php index de194f8..04450e6 100644 --- a/api/saved_filters.php +++ b/api/saved_filters.php @@ -17,6 +17,17 @@ if (!isset($_SESSION['user']) || !isset($_SESSION['user']['user_id'])) { exit; } +// CSRF Protection +require_once dirname(__DIR__) . '/middleware/CsrfMiddleware.php'; +if ($_SERVER['REQUEST_METHOD'] === 'POST' || $_SERVER['REQUEST_METHOD'] === 'PUT' || $_SERVER['REQUEST_METHOD'] === 'DELETE') { + $csrfToken = $_SERVER['HTTP_X_CSRF_TOKEN'] ?? ''; + if (!CsrfMiddleware::validateToken($csrfToken)) { + http_response_code(403); + echo json_encode(['success' => false, 'error' => 'Invalid CSRF token']); + exit; + } +} + $userId = $_SESSION['user']['user_id']; // Create database connection