diff --git a/scripts/pi-hole/js/customdns.js b/scripts/pi-hole/js/customdns.js index 9887d2bc..49e076c8 100644 --- a/scripts/pi-hole/js/customdns.js +++ b/scripts/pi-hole/js/customdns.js @@ -6,6 +6,7 @@ * Please see LICENSE file for your rights under this license. */ var table; +var token = $("#token").text(); function showAlert(type, message) { var alertElement = null; @@ -40,7 +41,11 @@ $(document).ready(function () { $("#btnAdd").on("click", addCustomDNS); table = $("#customDNSTable").DataTable({ - ajax: "scripts/pi-hole/php/customdns.php?action=get", + ajax: { + url: "scripts/pi-hole/php/customdns.php", + data: { action: "get", token: token }, + type: "POST" + }, columns: [{}, { type: "ip-address" }, { orderable: false, searchable: false }], columnDefs: [ { @@ -79,7 +84,7 @@ function addCustomDNS() { url: "scripts/pi-hole/php/customdns.php", method: "post", dataType: "json", - data: { action: "add", ip: ip, domain: domain }, + data: { action: "add", ip: ip, domain: domain, token: token }, success: function (response) { if (response.success) { showAlert("success"); @@ -101,7 +106,7 @@ function deleteCustomDNS() { url: "scripts/pi-hole/php/customdns.php", method: "post", dataType: "json", - data: { action: "delete", domain: domain, ip: ip }, + data: { action: "delete", domain: domain, ip: ip, token: token }, success: function (response) { if (response.success) { showAlert("success"); diff --git a/scripts/pi-hole/php/customdns.php b/scripts/pi-hole/php/customdns.php index a27f1e2b..b61eed4e 100644 --- a/scripts/pi-hole/php/customdns.php +++ b/scripts/pi-hole/php/customdns.php @@ -4,7 +4,18 @@ $customDNSFile = "/etc/pihole/custom.list"; - switch ($_REQUEST['action']) + require_once('auth.php'); + + // Authentication checks + if (isset($_POST['token'])) { + check_cors(); + check_csrf($_POST['token']); + } else { + log_and_die('Not allowed (login session invalid or expired, please relogin on the Pi-hole dashboard)!'); + } + + + switch ($_POST['action']) { case 'get': echo json_encode(echoCustomDNSEntries()); break; case 'add': echo json_encode(addCustomDNSEntry()); break; @@ -12,4 +23,6 @@ default: die("Wrong action"); } + + ?>