summaryrefslogtreecommitdiff
path: root/routes/create.py
diff options
context:
space:
mode:
authorMarjo Murtomäki <mmurtoma@local>2023-11-27 19:56:22 +0200
committerMarjo Murtomäki <mmurtoma@local>2023-11-27 19:56:22 +0200
commitc618290a4476fd01f46b079e8b95bbc16341cbca (patch)
tree9b74d598584d25b7b032d53da919d3338d0eb191 /routes/create.py
parentf965d5d1f799037cd49accae9256ed42b8c17ccb (diff)
Adding csrf checking to every post handler.
Diffstat (limited to 'routes/create.py')
-rw-r--r--routes/create.py2
1 files changed, 2 insertions, 0 deletions
diff --git a/routes/create.py b/routes/create.py
index 36c2521..c218d1f 100644
--- a/routes/create.py
+++ b/routes/create.py
@@ -41,6 +41,7 @@ def create():
@app.route("/set/quiz",methods=["POST"])
def new_quiz():
+ csrf_check("/#create")
if not "id" in session.keys():
session["alert"]="Tarvitset nimimerkin loudaksesi."
return redirect("/#create")
@@ -51,6 +52,7 @@ def new_quiz():
@app.route("/set/quiz_ready",methods=["POST"])
def quiz_ready():
+ csrf_check("/#create")
if "quiz_id" not in session.keys():
session["alert"] = "Kyselmä jota ei ole aloitettu ei voi olla valmis."
return redirect("/#create")