diff --git a/backend.php b/backend.php index e65ce1b94..1bbeec2bd 100644 --- a/backend.php +++ b/backend.php @@ -20,7 +20,7 @@ return; } - @$csrf_token = $_REQUEST['csrf_token']; + @$csrf_token = $_POST['csrf_token']; require_once "autoload.php"; require_once "sessions.php"; diff --git a/classes/feeds.php b/classes/feeds.php index 58ba1b6f8..71890f6ab 100755 --- a/classes/feeds.php +++ b/classes/feeds.php @@ -751,7 +751,7 @@ class Feeds extends Handler_Protected { $feed_id = (int)$_REQUEST["feed_id"]; @$do_update = $_REQUEST["action"] == "do_update"; - $csrf_token = $_REQUEST["csrf_token"]; + $csrf_token = $_POST["csrf_token"]; $sth = $this->pdo->prepare("SELECT id FROM ttrss_feeds WHERE id = ? AND owner_uid = ?"); $sth->execute([$feed_id, $_SESSION['uid']]); @@ -799,7 +799,7 @@ class Feeds extends Handler_Protected {