diff --git a/lib/Controller/PersonalSettingController.php b/lib/Controller/PersonalSettingController.php index 99bc65a..90fb758 100644 --- a/lib/Controller/PersonalSettingController.php +++ b/lib/Controller/PersonalSettingController.php @@ -54,6 +54,7 @@ class PersonalSettingController extends Controller /** * @NoAdminRequired + * @NoCSRFRequired * * @param mixed $name * @param mixed $value diff --git a/src/admin.js b/src/admin.js index 3058e24..92d1948 100644 --- a/src/admin.js +++ b/src/admin.js @@ -21,16 +21,17 @@ const selector = '#side-menu-message' const userConfig = (name, value, callbacks) => { const url = OC.generateUrl('/apps/side_menu/personalSetting/valueSet') - const formData = new FormData() - formData.append('name', name) - formData.append('value', value) + const formData = [] + + formData.push('name=' + encodeURIComponent(name)) + formData.push('value=' + encodeURIComponent(value)) fetch(url, { method: 'POST', headers: { 'Content-Type': 'application/x-www-form-urlencoded', }, - body: formData + body: formData.join('&') }) .then(callbacks.success) .catch(callbacks.error)