require auth for the customDNS page

Signed-off-by: Adam Warner <me@adamwarner.co.uk>
This commit is contained in:
Adam Warner
2020-05-20 08:26:21 +01:00
parent 0f9f33cb14
commit 7b2d396295
2 changed files with 22 additions and 4 deletions
+8 -3
View File
@@ -6,6 +6,7 @@
* Please see LICENSE file for your rights under this license. */
var table;
var token = $("#token").text();
function showAlert(type, message) {
var alertElement = null;
@@ -40,7 +41,11 @@ $(document).ready(function () {
$("#btnAdd").on("click", addCustomDNS);
table = $("#customDNSTable").DataTable({
ajax: "scripts/pi-hole/php/customdns.php?action=get",
ajax: {
url: "scripts/pi-hole/php/customdns.php",
data: { action: "get", token: token },
type: "POST"
},
columns: [{}, { type: "ip-address" }, { orderable: false, searchable: false }],
columnDefs: [
{
@@ -79,7 +84,7 @@ function addCustomDNS() {
url: "scripts/pi-hole/php/customdns.php",
method: "post",
dataType: "json",
data: { action: "add", ip: ip, domain: domain },
data: { action: "add", ip: ip, domain: domain, token: token },
success: function (response) {
if (response.success) {
showAlert("success");
@@ -101,7 +106,7 @@ function deleteCustomDNS() {
url: "scripts/pi-hole/php/customdns.php",
method: "post",
dataType: "json",
data: { action: "delete", domain: domain, ip: ip },
data: { action: "delete", domain: domain, ip: ip, token: token },
success: function (response) {
if (response.success) {
showAlert("success");
+14 -1
View File
@@ -4,7 +4,18 @@
$customDNSFile = "/etc/pihole/custom.list";
switch ($_REQUEST['action'])
require_once('auth.php');
// Authentication checks
if (isset($_POST['token'])) {
check_cors();
check_csrf($_POST['token']);
} else {
log_and_die('Not allowed (login session invalid or expired, please relogin on the Pi-hole dashboard)!');
}
switch ($_POST['action'])
{
case 'get': echo json_encode(echoCustomDNSEntries()); break;
case 'add': echo json_encode(addCustomDNSEntry()); break;
@@ -12,4 +23,6 @@
default:
die("Wrong action");
}
?>