Skip to content

Commit 9b2dd65

Browse files
committed
Switch GET to POST for asset request
Signed-off-by: snipe <[email protected]>
1 parent a05fe9c commit 9b2dd65

File tree

4 files changed

+5
-5
lines changed

4 files changed

+5
-5
lines changed

app/Http/Controllers/ViewAssetsController.php

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -179,7 +179,7 @@ public function getRequestAsset($assetId = null)
179179
$logaction->logaction('request canceled');
180180
$settings->notify(new RequestAssetCancelation($data));
181181
return redirect()->route('requestable-assets')
182-
->with('success')->with('success', trans('admin/hardware/message.requests.cancel-success'));
182+
->with('success')->with('success', trans('admin/hardware/message.requests.cancel'));
183183
}
184184

185185
$logaction->logaction('requested');

resources/lang/en/admin/hardware/message.php

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -77,7 +77,7 @@
7777
'requests' => array(
7878
'error' => 'Asset was not requested, please try again',
7979
'success' => 'Asset requested successfully.',
80-
'canceled' => 'Checkout request successfully canceled'
80+
'cancel' => 'Checkout request successfully canceled'
8181
)
8282

8383
);

resources/views/partials/bootstrap-table.blade.php

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -365,9 +365,9 @@ function genericCheckinCheckoutFormatter(destination) {
365365
// This is only used by the requestable assets section
366366
function assetRequestActionsFormatter (row, value) {
367367
if (value.available_actions.cancel == true) {
368-
return '<form action="{{ url('/') }}/account/request-asset/'+ value.id + '" method="GET"><button class="btn btn-danger btn-sm" data-toggle="tooltip" title="Cancel this item request">{{ trans('button.cancel') }}</button></form>';
368+
return '<form action="{{ url('/') }}/account/request-asset/'+ value.id + '" method="POST">@csrf<button class="btn btn-danger btn-sm" data-toggle="tooltip" title="Cancel this item request">{{ trans('button.cancel') }}</button></form>';
369369
} else if (value.available_actions.request == true) {
370-
return '<form action="{{ url('/') }}/account/request-asset/'+ value.id + '" method="GET"><button class="btn btn-primary btn-sm" data-toggle="tooltip" title="Request this item">{{ trans('button.request') }}</button></form>';
370+
return '<form action="{{ url('/') }}/account/request-asset/'+ value.id + '" method="POST">@csrf<button class="btn btn-primary btn-sm" data-toggle="tooltip" title="Request this item">{{ trans('button.request') }}</button></form>';
371371
}
372372
373373
}

routes/web.php

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -261,7 +261,7 @@
261261
'requestable-assets',
262262
[ 'as' => 'requestable-assets', 'uses' => 'ViewAssetsController@getRequestableIndex' ]
263263
);
264-
Route::get(
264+
Route::post(
265265
'request-asset/{assetId}',
266266
[ 'as' => 'account/request-asset', 'uses' => 'ViewAssetsController@getRequestAsset' ]
267267
);

0 commit comments

Comments
 (0)