summaryrefslogtreecommitdiff
path: root/templates
diff options
context:
space:
mode:
authorKalevi Yypänaho <kyypanah@local>2023-11-27 20:35:57 +0200
committerKalevi Yypänaho <kyypanah@local>2023-11-27 20:35:57 +0200
commitd74aca91c689b54b7b49bbfa7121f458f4caf751 (patch)
treeb13f1ffc7d6f5c816ac16147cc9b8703a17c69c7 /templates
parentd6c73dbde8a35905a8f29caf9b6d088043a5e78f (diff)
Adding csrf to templates.
Diffstat (limited to 'templates')
-rw-r--r--templates/analyse.html6
-rw-r--r--templates/answer.html2
-rw-r--r--templates/base.html1
-rw-r--r--templates/create.html2
-rw-r--r--templates/question.html1
5 files changed, 12 insertions, 0 deletions
diff --git a/templates/analyse.html b/templates/analyse.html
index b7139e4..6dcc1be 100644
--- a/templates/analyse.html
+++ b/templates/analyse.html
@@ -26,6 +26,7 @@ Tutkit kyselmää: {{ code }}
{% endif %}
{% endfor %}
</select>
+<input type="text" name="csrf" value="{{ session.csrf }}" hidden="true">
<input type="submit" value="Vertaa" class="kysButton">
</form>
</div></div>
@@ -60,6 +61,7 @@ Tutkit kyselmää: {{ code }}
<form action="/set/compare" method="POST">
<input type="text" name="user1" hidden="true" value={{ best.max_u1 }}>
<input type="text" name="user2" hidden="true" value={{ best.max_u2 }}>
+<input type="text" name="csrf" value="{{ session.csrf }}" hidden="true">
<input type="submit" value="Kaikista paras yhtäläisyys ({{ best.max }}%)"
class="kysButton">
</form>
@@ -67,6 +69,7 @@ Tutkit kyselmää: {{ code }}
<form action="/set/compare" method="POST">
<input type="text" name="user1" hidden="true" value={{ best.maxme_u1 }}>
<input type="text" name="user2" hidden="true" value={{ best.maxme_u2 }}>
+<input type="text" name="csrf" value="{{ session.csrf }}" hidden="true">
<input type="submit" value="Paras yhtäläisyys kanssani ({{ best.maxme }}%)"
class="kysButton">
</form>
@@ -74,6 +77,7 @@ Tutkit kyselmää: {{ code }}
<form action="/set/compare" method="POST">
<input type="text" name="user1" hidden="true" value={{ best.minme_u1 }}>
<input type="text" name="user2" hidden="true" value={{ best.minme_u2 }}>
+<input type="text" name="csrf" value="{{ session.csrf }}" hidden="true">
<input type="submit" value="Huonoin yhtäläisyys kanssani ({{ best.minme }}%)"
class="kysButton">
</form>
@@ -81,6 +85,7 @@ Tutkit kyselmää: {{ code }}
<form action="/set/compare" method="POST">
<input type="text" name="user1" hidden="true" value={{ best.min_u1 }}>
<input type="text" name="user2" hidden="true" value={{ best.min_u2 }}>
+<input type="text" name="csrf" value="{{ session.csrf }}" hidden="true">
<input type="submit" value="Kaikista huonoin yhtäläisyys ({{ best.min }}%)"
class="kysButton">
</form>
@@ -93,6 +98,7 @@ Tutkit kyselmää: {{ code }}
Vaihda kyselyn koodia:
<input type="text" name="link">
<input type="text" name="caller" value="analyse" hidden="true">
+<input type="text" name="csrf" value="{{ session.csrf }}" hidden="true">
<input type="submit" value="Vaihda">
</form>
diff --git a/templates/answer.html b/templates/answer.html
index 6231785..4bf61d3 100644
--- a/templates/answer.html
+++ b/templates/answer.html
@@ -18,6 +18,7 @@ Vastaa kyselmään "{{ link }}":
<input class="kysAnswer" type="range" min="0" max="999" name="{{ q.i }}">
</div>
{% endfor %}
+<input type="text" name="csrf" value="{{ session.csrf }}" hidden="true">
<input class="kysSubmitAnswers" type="submit" value="Vastaa kyselyyn">
</div>
</form>
@@ -28,6 +29,7 @@ Vastaa kyselmään "{{ link }}":
Vastaa kyselyyn koodilla:
<input type="text" name="link">
<input type="text" name="caller" value="answer" hidden="true">
+<input type="text" name="csrf" value="{{ session.csrf }}" hidden="true">
<input type="submit" value="Kyselmään">
</form>
diff --git a/templates/base.html b/templates/base.html
index f38eb12..e47e643 100644
--- a/templates/base.html
+++ b/templates/base.html
@@ -5,6 +5,7 @@
Anna itsellesi nimimerkki ensin:
<input type="text" name="nick">
<input type="text" name="caller" value="{{ caller }}" hidden="true">
+<input type="text" name="csrf" value="{{ session.csrf }}" hidden="true">
<input type="submit" value="Lähetä">
</form>
{% endif %}
diff --git a/templates/create.html b/templates/create.html
index 21520b5..eb4bccd 100644
--- a/templates/create.html
+++ b/templates/create.html
@@ -25,6 +25,7 @@
<div class="kysScaleSpacer"></div>
<form action="/set/quiz_ready" method="POST">
<input type="text" name="ok" hidden=true>
+<input type="text" name="csrf" value="{{ session.csrf }}" hidden="true">
<input type="submit" value="Valmis" class="kysButton">
</form>
<div class="kysScale">
@@ -34,6 +35,7 @@
{% else %}
<form action="/set/quiz" method="POST">
+<input type="text" name="csrf" value="{{ session.csrf }}" hidden="true">
<input type="submit" value="Aloita uusi kyselmä">
</form>
diff --git a/templates/question.html b/templates/question.html
index 62afaaf..76cba79 100644
--- a/templates/question.html
+++ b/templates/question.html
@@ -12,6 +12,7 @@
<input type="range" min="0" max="999" value="500"
class="kysAnswer" name="answer" >
+<input type="text" name="csrf" value="{{ session.csrf }}" hidden="true">
<input type="submit" value="Lisää kysymys">
</div>
</form>