aboutsummaryrefslogtreecommitdiffstats
path: root/view
diff options
context:
space:
mode:
authorgit-marijus <mario@mariovavti.com>2017-03-31 13:40:02 +0200
committerGitHub <noreply@github.com>2017-03-31 13:40:02 +0200
commit89e3f3210f5d8ddd49386a5c16320c4d2b909906 (patch)
treec6db28288c69264b0eb962c4caa3569c92dc8cda /view
parentdc55c710da8b52c9a8e60663ad00aae28bbc8c6b (diff)
parent81736a01299f7c963e361e9b192df074999d16d8 (diff)
downloadvolse-hubzilla-89e3f3210f5d8ddd49386a5c16320c4d2b909906.tar.gz
volse-hubzilla-89e3f3210f5d8ddd49386a5c16320c4d2b909906.tar.bz2
volse-hubzilla-89e3f3210f5d8ddd49386a5c16320c4d2b909906.zip
Merge pull request #710 from dawnbreak/importcsrf
:lock: Add CSRF protection for import and import_items.
Diffstat (limited to 'view')
-rwxr-xr-xview/tpl/channel_import.tpl5
-rwxr-xr-xview/tpl/item_import.tpl4
2 files changed, 2 insertions, 7 deletions
diff --git a/view/tpl/channel_import.tpl b/view/tpl/channel_import.tpl
index 2028d6181..baffe9b06 100755
--- a/view/tpl/channel_import.tpl
+++ b/view/tpl/channel_import.tpl
@@ -1,7 +1,7 @@
<h2>{{$title}}</h2>
<form action="import" method="post" enctype="multipart/form-data" id="import-channel-form">
-
+ <input type="hidden" name="form_security_token" value="{{$form_security_token}}">
<div id="import-desc" class="descriptive-paragraph">{{$desc}}</div>
<label for="import-filename" id="label-import-filename" class="import-label" >{{$label_filename}}</label>
@@ -40,7 +40,4 @@
<div id="import-submit-end" class="import-field-end"></div>
<div id="import-common-desc" class="descriptive-paragraph">{{$pleasewait}}</div>
-
-
</form>
-
diff --git a/view/tpl/item_import.tpl b/view/tpl/item_import.tpl
index 65de7fcaf..e976417e1 100755
--- a/view/tpl/item_import.tpl
+++ b/view/tpl/item_import.tpl
@@ -1,7 +1,7 @@
<h2>{{$title}}</h2>
<form action="import_items" method="post" enctype="multipart/form-data" id="import-channel-form">
-
+ <input type="hidden" name="form_security_token" value="{{$form_security_token}}">
<div id="import-desc" class="descriptive-paragraph">{{$desc}}</div>
<label for="import-filename" id="label-import-filename" class="import-label" >{{$label_filename}}</label>
@@ -10,6 +10,4 @@
<input type="submit" name="submit" id="import-submit-button" value="{{$submit}}" />
<div id="import-submit-end" class="import-field-end"></div>
-
</form>
-