fix hall creation
This commit is contained in:
@@ -269,6 +269,9 @@ export const handleHallUpdate = async (req, res) => {
|
|||||||
|
|
||||||
// POST /api/v2/admin/halls — create a new hall
|
// POST /api/v2/admin/halls — create a new hall
|
||||||
export const handleHallCreate = async (req, res) => {
|
export const handleHallCreate = async (req, res) => {
|
||||||
|
const session = await lookupSession(req);
|
||||||
|
if (!session || (!session.admin && !session.is_moderator)) return sendJson(res, { success: false, msg: 'Unauthorized' }, 403);
|
||||||
|
|
||||||
// CSRF check
|
// CSRF check
|
||||||
const token = req.headers['x-csrf-token'] || req.url?.qs?.csrf_token;
|
const token = req.headers['x-csrf-token'] || req.url?.qs?.csrf_token;
|
||||||
if (!token || token !== session.csrf_token) {
|
if (!token || token !== session.csrf_token) {
|
||||||
|
|||||||
Reference in New Issue
Block a user