From 5d24dce3d819a2d4a1ca0f61c778bb32004f4551 Mon Sep 17 00:00:00 2001
From: Timothee Gosselin <timothee@unteem.org>
Date: Mon, 7 Jan 2019 15:17:47 +0100
Subject: [PATCH] add headers for CRSF check

---
 utils/add_cloud_user | 6 +++---
 1 file changed, 3 insertions(+), 3 deletions(-)

diff --git a/utils/add_cloud_user b/utils/add_cloud_user
index 01ca7c5..74bc628 100755
--- a/utils/add_cloud_user
+++ b/utils/add_cloud_user
@@ -6,6 +6,6 @@ user=$1
 email=$2
 quota=$3
 
-curl -X POST --user ${cloud_admin}:${cloud_pass} https://${cloud_hostname}/ocs/v1.php/cloud/users -d userid="$1" -d password="`tr -dc A-Za-z0-9_ < /dev/urandom | head -c 10 | xargs`"
-curl -X PUT --user ${cloud_admin}:${cloud_pass} https://${cloud_hostname}/ocs/v1.php/cloud/users/${user} -d key="email" -d value="${email}"
-curl -X PUT --user ${cloud_admin}:${cloud_pass} https://${cloud_hostname}/ocs/v1.php/cloud/users/${user} -d key="quota" -d value="${quota}"
+curl -X POST -H "OCS-APIRequest:true" --user ${cloud_admin}:${cloud_pass} https://${cloud_hostname}/ocs/v1.php/cloud/users -d userid="$1" -d password="`tr -dc A-Za-z0-9_ < /dev/urandom | head -c 10 | xargs`"
+curl -X PUT -H "OCS-APIRequest:true" --user ${cloud_admin}:${cloud_pass} https://${cloud_hostname}/ocs/v1.php/cloud/users/${user} -d key="email" -d value="${email}"
+curl -X PUT -H "OCS-APIRequest:true" --user ${cloud_admin}:${cloud_pass} https://${cloud_hostname}/ocs/v1.php/cloud/users/${user} -d key="quota" -d value="${quota}"
-- 
GitLab