API call to modify local CNAME records

Signed-off-by: Alexandr Salamatov <wpgnetworks@gmail.com>
This commit is contained in:
Alexandr Salamatov
2022-01-20 21:22:01 -06:00
parent dc598295ca
commit 39f0da7eb5
2 changed files with 34 additions and 5 deletions
+27
View File
@@ -168,6 +168,33 @@ elseif(isset($_GET['customdns']) && $auth)
require("scripts/pi-hole/php/customdns.php");
}
elseif(isset($_GET['customcname']) && $auth)
{
if(isset($_GET["auth"]))
{
if($_GET["auth"] !== $pwhash)
die("Not authorized!");
}
else
{
// Skip token validation if explicit auth string is given
check_csrf($_GET['token']);
}
switch ($_GET["action"]) {
case 'get':
$_POST['action'] = 'get';
break;
case 'add':
$_POST['action'] = 'add';
break;
case 'delete':
$_POST['action'] = 'delete';
break;
}
require("scripts/pi-hole/php/customcname.php");
}
// Other API functions
require("api_FTL.php");
+7 -5
View File
@@ -5,11 +5,13 @@
require_once('auth.php');
// Authentication checks
if (isset($_POST['token'])) {
check_cors();
check_csrf($_POST['token']);
} else {
log_and_die('Not allowed (login session invalid or expired, please relogin on the Pi-hole dashboard)!');
if (!isset($api)) {
if (isset($_POST['token'])) {
check_cors();
check_csrf($_POST['token']);
} else {
log_and_die('Not allowed (login session invalid or expired, please relogin on the Pi-hole dashboard)!');
}
}