Issue 361: Include the CSRF token in all forms

This commit is contained in:
Nathan Yergler 2011-09-04 18:16:03 -07:00
parent f1226c98c4
commit 0a8a3fc157
9 changed files with 9 additions and 0 deletions

View File

@ -22,6 +22,7 @@
{% block mediagoblin_content %} {% block mediagoblin_content %}
<form action="{{ request.urlgen('mediagoblin.auth.login') }}" <form action="{{ request.urlgen('mediagoblin.auth.login') }}"
method="POST" enctype="multipart/form-data"> method="POST" enctype="multipart/form-data">
{{ csrf_token }}
<div class="grid_6 prefix_1 suffix_1 form_box"> <div class="grid_6 prefix_1 suffix_1 form_box">
<h1>{% trans %}Log in{% endtrans %}</h1> <h1>{% trans %}Log in{% endtrans %}</h1>
{% if login_failed %} {% if login_failed %}

View File

@ -26,6 +26,7 @@
<div class="grid_6 prefix_1 suffix_1 form_box"> <div class="grid_6 prefix_1 suffix_1 form_box">
<h1>{% trans %}Create an account!{% endtrans %}</h1> <h1>{% trans %}Create an account!{% endtrans %}</h1>
{{ wtforms_util.render_divs(register_form) }} {{ wtforms_util.render_divs(register_form) }}
{{ csrf_token }}
<div class="form_submit_buttons"> <div class="form_submit_buttons">
<input type="submit" value="{% trans %}Create{% endtrans %}" <input type="submit" value="{% trans %}Create{% endtrans %}"
class="button" /> class="button" />

View File

@ -49,6 +49,7 @@
<div class="form_submit_buttons"> <div class="form_submit_buttons">
<a href="{{ media.url_for_self(request.urlgen) }}">Cancel</a> <a href="{{ media.url_for_self(request.urlgen) }}">Cancel</a>
<input type="submit" value="Save changes" class="button" /> <input type="submit" value="Save changes" class="button" />
{{ csrf_token }}
</div> </div>
</div> </div>
</form> </form>

View File

@ -35,6 +35,7 @@
<div class="form_submit_buttons"> <div class="form_submit_buttons">
<a href="{{ media.url_for_self(request.urlgen) }}">{% trans %}Cancel{% endtrans %}</a> <a href="{{ media.url_for_self(request.urlgen) }}">{% trans %}Cancel{% endtrans %}</a>
<input type="submit" value="{% trans %}Save changes{% endtrans %}" class="button" /> <input type="submit" value="{% trans %}Save changes{% endtrans %}" class="button" />
{{ csrf_token }}
</div> </div>
</div> </div>
</form> </form>

View File

@ -33,6 +33,7 @@
{{ wtforms_util.render_divs(form) }} {{ wtforms_util.render_divs(form) }}
<div class="form_submit_buttons"> <div class="form_submit_buttons">
<input type="submit" value="{% trans %}Save changes{% endtrans %}" class="button" /> <input type="submit" value="{% trans %}Save changes{% endtrans %}" class="button" />
{{ csrf_token }}
</div> </div>
</div> </div>
</form> </form>

View File

@ -26,6 +26,7 @@
<h1>{% trans %}Submit yer media{% endtrans %}</h1> <h1>{% trans %}Submit yer media{% endtrans %}</h1>
{{ wtforms_util.render_divs(submit_form) }} {{ wtforms_util.render_divs(submit_form) }}
<div class="form_submit_buttons"> <div class="form_submit_buttons">
{{ csrf_token }}
<input type="submit" value="{% trans %}Submit{% endtrans %}" class="button" /> <input type="submit" value="{% trans %}Submit{% endtrans %}" class="button" />
</div> </div>
</div> </div>

View File

@ -26,6 +26,7 @@
<tr> <tr>
<td></td> <td></td>
<td><input type="submit" value="submit" class="button" /></td> <td><input type="submit" value="submit" class="button" /></td>
{{ csrf_token }}
</tr> </tr>
</table> </table>
</form> </form>

View File

@ -72,6 +72,7 @@
{{ wtforms_util.render_divs(comment_form) }} {{ wtforms_util.render_divs(comment_form) }}
<div class="form_submit_buttons"> <div class="form_submit_buttons">
<input type="submit" value="{% trans %}Post comment!{% endtrans %}" class="button" /> <input type="submit" value="{% trans %}Post comment!{% endtrans %}" class="button" />
{{ csrf_token }}
</div> </div>
</form> </form>
{% endif %} {% endif %}

View File

@ -42,6 +42,7 @@
{{ wtforms_util.render_divs(form) }} {{ wtforms_util.render_divs(form) }}
<div class="form_submit_buttons"> <div class="form_submit_buttons">
<input type="submit" value="{% trans %}Save changes{% endtrans %}" class="button" /> <input type="submit" value="{% trans %}Save changes{% endtrans %}" class="button" />
{{ csrf_token }}
</div> </div>
</div> </div>
</form> </form>