From c618290a4476fd01f46b079e8b95bbc16341cbca Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?Marjo=20Murtom=C3=A4ki?= Date: Mon, 27 Nov 2023 19:56:22 +0200 Subject: Adding csrf checking to every post handler. --- routes/answer.py | 2 ++ 1 file changed, 2 insertions(+) (limited to 'routes/answer.py') diff --git a/routes/answer.py b/routes/answer.py index 2fbeec8..6d767be 100644 --- a/routes/answer.py +++ b/routes/answer.py @@ -14,6 +14,7 @@ def kys_link(link): @app.route("/set/answer_id",methods=["POST"]) def answer_id(): next = "/#"+request.form["caller"] if "caller" in request.form else "/" + csrf_check(next) if "id" not in session: session["alert"] = "Nimimerkkiä ei ole asetettu." return redirect(next) @@ -81,6 +82,7 @@ def answer(): @app.route("/set/answers",methods=["POST"]) def set_answers(): + csrf_check("/#answer") if "id" not in session: session["alert"]="Nimimerkkiä ei ole vielä valittu!" return redirect( "/#answer" ) -- cgit v1.2.3