views: add missing @login_required restrictions

Add checks for logged user in folder/add and folder/update
endpoints.
master v1.1.3-37
Alejandro Sirgo Rica 2024-12-17 14:00:36 +01:00
parent f75a72b1cf
commit 655ffbc0bb
1 changed files with 2 additions and 0 deletions

View File

@ -1651,6 +1651,7 @@ def action_folder_delete():
@app.route('/action/folder/update', methods=['GET','POST'])
@handle_server_errors('scopes')
@login_required
def action_folder_update():
form = FolderForm(request.form)
if request.method == 'POST':
@ -1705,6 +1706,7 @@ def action_folder_add():
@app.route('/action/folder/add', methods=['POST'])
@handle_server_errors('scopes')
@login_required
def action_folder_add_post():
form = FolderForm(request.form)
payload = {"name": form.name.data}