mirror of
https://github.com/grocy/grocy.git
synced 2025-08-16 10:44:37 +00:00
Sanitize user input on all API routes (references #996)
This commit is contained in:
@@ -10,7 +10,7 @@ class RecipesApiController extends BaseApiController
|
||||
{
|
||||
User::checkPermission($request, User::PERMISSION_SHOPPINGLIST_ITEMS_ADD);
|
||||
|
||||
$requestBody = $request->getParsedBody();
|
||||
$requestBody = $this->GetParsedAndFilteredRequestBody($request);
|
||||
$excludedProductIds = null;
|
||||
|
||||
if ($requestBody !== null && array_key_exists('excludedProductIds', $requestBody))
|
||||
|
Reference in New Issue
Block a user