Issue 361: Include the CSRF token in all forms
authorNathan Yergler <nathan@yergler.net>
Mon, 5 Sep 2011 01:16:03 +0000 (18:16 -0700)
committerNathan Yergler <nathan@yergler.net>
Mon, 5 Sep 2011 01:16:03 +0000 (18:16 -0700)
mediagoblin/templates/mediagoblin/auth/login.html
mediagoblin/templates/mediagoblin/auth/register.html
mediagoblin/templates/mediagoblin/edit/attachments.html
mediagoblin/templates/mediagoblin/edit/edit.html
mediagoblin/templates/mediagoblin/edit/edit_profile.html
mediagoblin/templates/mediagoblin/submit/start.html
mediagoblin/templates/mediagoblin/test_submit.html
mediagoblin/templates/mediagoblin/user_pages/media.html
mediagoblin/templates/mediagoblin/user_pages/media_confirm_delete.html

index 958cf9eacbd80daaaab35a5add98c9fb6ebc763a..1be58560b09657c8ab089cfee6124a885998c622 100644 (file)
@@ -22,6 +22,7 @@
 {% block mediagoblin_content %}
   <form action="{{ request.urlgen('mediagoblin.auth.login') }}"
         method="POST" enctype="multipart/form-data">
+    {{ csrf_token }}
     <div class="grid_6 prefix_1 suffix_1 form_box">
       <h1>{% trans %}Log in{% endtrans %}</h1>
       {% if login_failed %}
index e72b3a528425d43bf068129fc5f5ae4f850a1b5f..25b68058b04631d5989ad76c606dbd7d0555a024 100644 (file)
@@ -26,6 +26,7 @@
     <div class="grid_6 prefix_1 suffix_1 form_box">
       <h1>{% trans %}Create an account!{% endtrans %}</h1>
       {{ wtforms_util.render_divs(register_form) }}
+      {{ csrf_token }}
       <div class="form_submit_buttons">
         <input type="submit" value="{% trans %}Create{% endtrans %}"
                class="button" />
index 63b0658176e41db0f79d3fc95c5a2c0d53272f39..d8b55f58dbcdcf9ea4497eaac373dab7e98ca31f 100644 (file)
@@ -49,6 +49,7 @@
       <div class="form_submit_buttons">
         <a href="{{ media.url_for_self(request.urlgen) }}">Cancel</a>
         <input type="submit" value="Save changes" class="button" />
+       {{ csrf_token }}
       </div>
     </div>
   </form>
index 8c4e2efb563e5fb05b7eceb1b891001bd7a73c82..b4b3be85f16d8db4fa3d850073afd566ad188cbd 100644 (file)
@@ -35,6 +35,7 @@
       <div class="form_submit_buttons">
         <a href="{{ media.url_for_self(request.urlgen) }}">{% trans %}Cancel{% endtrans %}</a>
         <input type="submit" value="{% trans %}Save changes{% endtrans %}" class="button" />
+       {{ csrf_token }}
       </div>
     </div>
   </form>
index 464c663da160db93821e174d101b54806424f271..93b2a792a70e3edb2f0eab3470287036c508b533 100644 (file)
@@ -33,6 +33,7 @@
       {{ wtforms_util.render_divs(form) }}
       <div class="form_submit_buttons">
         <input type="submit" value="{% trans %}Save changes{% endtrans %}" class="button" />
+       {{ csrf_token }}
       </div>
     </div>
   </form>
index f2e844df8da615c8d487cc157dc23628a31df4dc..7bc6ff45afc93bc7ac581a259a2984cdf6713b82 100644 (file)
@@ -26,6 +26,7 @@
       <h1>{% trans %}Submit yer media{% endtrans %}</h1>
       {{ wtforms_util.render_divs(submit_form) }}
       <div class="form_submit_buttons">
+      {{ csrf_token }}
       <input type="submit" value="{% trans %}Submit{% endtrans %}" class="button" />
       </div>
     </div>
index 78b88ae86fe5af92fce87c2231ed9ea1f603d2db..190b9ac3232164aea0d482ab28b72a5af1bddc3c 100644 (file)
@@ -26,6 +26,7 @@
         <tr>
           <td></td>
           <td><input type="submit" value="submit" class="button" /></td>
+         {{ csrf_token }}
         </tr>
       </table>
     </form>
index 442bef6da27d762609ab8ebb74e158327a35a44a..433f74dcac73dcd96dd2ed97bd6c86fe3f2d1a41 100644 (file)
@@ -72,6 +72,7 @@
           {{ wtforms_util.render_divs(comment_form) }}
           <div class="form_submit_buttons">
             <input type="submit" value="{% trans %}Post comment!{% endtrans %}" class="button" />
+           {{ csrf_token }}
           </div>
         </form>
       {% endif %}
index 48fbc3b04ba55ef3b94ec96d2f7b6ccc3d8c1b87..3acf802b817cacc475f91e5124a2cd2d6ec5ec69 100644 (file)
@@ -42,6 +42,7 @@
       {{ wtforms_util.render_divs(form) }}
       <div class="form_submit_buttons">
         <input type="submit" value="{% trans %}Save changes{% endtrans %}" class="button" />
+       {{ csrf_token }}
       </div>
     </div>
   </form>