Commit 2cd7bed9 authored by Primsi's avatar Primsi
Browse files

by primsi: require _csrf_token for dropzonejs.upload route.

parent 721e5175
......@@ -4,3 +4,4 @@ dropzonejs.upload:
_controller: '\Drupal\dropzonejs\Controller\UploadController::handleUploads'
requirements:
_permission: 'dropzone upload files'
_csrf_token: 'TRUE'
......@@ -78,7 +78,7 @@ class DropzoneJs extends FormElement {
*/
public static function preRenderDropzoneJs($element) {
$element['#attached']['drupalSettings']['dropzonejs'] = [
'upload_path' => base_path() . 'dropzonejs/upload',
'upload_path' => \Drupal::url('dropzonejs.upload'),
'instances' => [
$element['#id'] => [
'maxFilesize' => $element['#max_filesize'],
......
Markdown is supported
0% or .
You are about to add 0 people to the discussion. Proceed with caution.
Finish editing this message first!
Please register or to comment