From c618290a4476fd01f46b079e8b95bbc16341cbca Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?Marjo=20Murtom=C3=A4ki?= Date: Mon, 27 Nov 2023 19:56:22 +0200 Subject: Adding csrf checking to every post handler. --- routes/base.py | 1 + 1 file changed, 1 insertion(+) (limited to 'routes/base.py') diff --git a/routes/base.py b/routes/base.py index 22245c5..6d6dcd8 100644 --- a/routes/base.py +++ b/routes/base.py @@ -25,6 +25,7 @@ def info(): @app.route("/set/nick",methods=["POST"]) def new_nick(): next = "/#"+request.form["caller"] if "caller" in request.form else "/" + csrf_check(next) if "id" in session.keys(): session["alert"]="Sinulla on jo nimimerkki. Käytä sitä." return redirect(next) -- cgit v1.2.3