From d74aca91c689b54b7b49bbfa7121f458f4caf751 Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?Kalevi=20Yyp=C3=A4naho?= Date: Mon, 27 Nov 2023 20:35:57 +0200 Subject: Adding csrf to templates. --- routes/base.py | 4 +++- 1 file changed, 3 insertions(+), 1 deletion(-) (limited to 'routes/base.py') diff --git a/routes/base.py b/routes/base.py index 42d8cdf..2c4b1f2 100644 --- a/routes/base.py +++ b/routes/base.py @@ -1,3 +1,4 @@ +from secrets import token_urlsafe from app import app from flask import render_template,session,request,redirect import db_actions as D @@ -26,7 +27,8 @@ def info(): @app.route("/set/nick",methods=["POST"]) def new_nick(): next = "/#"+request.form["caller"] if "caller" in request.form else "/" - csrf_check(next) + if csrf_check(): + return redirect(next) if "id" in session.keys(): session["alert"]="Sinulla on jo nimimerkki. Käytä sitä." return redirect(next) -- cgit v1.2.3