add CSRF validation

This commit is contained in:
Franzi 2021-12-21 16:57:39 +01:00
parent ae5a18138b
commit e32089c81e
Signed by: kunsi
GPG key ID: 12E3D2136B818350
5 changed files with 21 additions and 1 deletions

View file

@ -16,6 +16,7 @@
<td>{{ member["cn"] }}</td>
<td>
<form action="{{ url_for("group_edit", ou=ou) }}" method="post">
<input type="hidden" name="csrf_token" value="{{ csrf_token() }}"/>
<input type="hidden" name="remove" value="{{ member["uid"] }}">
<input type="submit" value="remove" class="btn btn-danger">
</form>
@ -25,6 +26,7 @@
</tbody>
</table>
<form action="{{ url_for("group_edit", ou=ou) }}" method="post" class="row g-3 needs-validation">
<input type="hidden" name="csrf_token" value="{{ csrf_token() }}"/>
<fieldset>
<legend>add user to group</legend>