Use POST for destructive actions & mobile UI tweaks
Require POST and CSRF verification for destructive endpoints (profile delete, notification delete, clear-all) and update routes accordingly. Replace GET-based delete links with POST forms (including csrf_field()) and add hidden form submission for "clear all" and account deletion via JS. Add server-side request method checks and verifyCsrf() calls in NotificationController and ProfileController. Improve mobile UX: add sidebar overlay, open/close controls (including swipe-to-close), close button, prevent body scroll when sidebar open, responsive search placeholder and adjusted search/top-nav styling, and minor layout tweaks (truncate app name, adjust notification dropdown width). Also minor whitespace/formatting cleanups.
This commit is contained in:
@@ -135,7 +135,7 @@ $router->post('/settings/toggle-isolation', [SettingsController::class, 'toggleI
|
||||
$router->get('/profile', [ProfileController::class, 'index']);
|
||||
$router->post('/profile/update', [ProfileController::class, 'update']);
|
||||
$router->post('/profile/change-password', [ProfileController::class, 'changePassword']);
|
||||
$router->get('/profile/delete', [ProfileController::class, 'delete']);
|
||||
$router->post('/profile/delete', [ProfileController::class, 'delete']);
|
||||
$router->get('/profile/resend-verification', [ProfileController::class, 'resendVerification']);
|
||||
$router->post('/profile/logout-other-sessions', [ProfileController::class, 'logoutOtherSessions']);
|
||||
$router->post('/profile/logout-session/{sessionId}', [ProfileController::class, 'logoutSession']);
|
||||
@@ -154,8 +154,8 @@ $router->post('/2fa/regenerate-backup-codes', [TwoFactorController::class, 'rege
|
||||
$router->get('/notifications', [NotificationController::class, 'index']);
|
||||
$router->get('/notifications/{id}/mark-read', [NotificationController::class, 'markAsRead']);
|
||||
$router->get('/notifications/mark-all-read', [NotificationController::class, 'markAllAsRead']);
|
||||
$router->get('/notifications/{id}/delete', [NotificationController::class, 'delete']);
|
||||
$router->get('/notifications/clear-all', [NotificationController::class, 'clearAll']);
|
||||
$router->post('/notifications/{id}/delete', [NotificationController::class, 'delete']);
|
||||
$router->post('/notifications/clear-all', [NotificationController::class, 'clearAll']);
|
||||
$router->get('/api/notifications/unread-count', [NotificationController::class, 'getUnreadCount']);
|
||||
$router->get('/api/notifications/recent', [NotificationController::class, 'getRecent']);
|
||||
|
||||
|
||||
Reference in New Issue
Block a user