diff options
author | Marjo Murtomäki <mmurtoma@local> | 2023-11-27 19:56:22 +0200 |
---|---|---|
committer | Marjo Murtomäki <mmurtoma@local> | 2023-11-27 19:56:22 +0200 |
commit | c618290a4476fd01f46b079e8b95bbc16341cbca (patch) | |
tree | 9b74d598584d25b7b032d53da919d3338d0eb191 /routes/create.py | |
parent | f965d5d1f799037cd49accae9256ed42b8c17ccb (diff) |
Adding csrf checking to every post handler.
Diffstat (limited to 'routes/create.py')
-rw-r--r-- | routes/create.py | 2 |
1 files changed, 2 insertions, 0 deletions
diff --git a/routes/create.py b/routes/create.py index 36c2521..c218d1f 100644 --- a/routes/create.py +++ b/routes/create.py @@ -41,6 +41,7 @@ def create(): @app.route("/set/quiz",methods=["POST"]) def new_quiz(): + csrf_check("/#create") if not "id" in session.keys(): session["alert"]="Tarvitset nimimerkin loudaksesi." return redirect("/#create") @@ -51,6 +52,7 @@ def new_quiz(): @app.route("/set/quiz_ready",methods=["POST"]) def quiz_ready(): + csrf_check("/#create") if "quiz_id" not in session.keys(): session["alert"] = "Kyselmä jota ei ole aloitettu ei voi olla valmis." return redirect("/#create") |