Fossil SCM

Add missing CSRF token to the new Attach button.

stephan 2026-05-23 07:45 UTC forum-attachments
Commit 2302e4141ce6a5b1c4a8296e32d198e52cc0aabe7b2f313aa7bb14654b6c3a44
1 file changed +1
--- src/forum.c
+++ src/forum.c
@@ -989,10 +989,11 @@
989989
}
990990
if( g.perm.Admin || forumpost_is_owner(p/*not pHead*/->fpid, 0) ){
991991
@ <form method="post" action="%R/attachadd">\
992992
@ <input type="hidden" name="forumpost" value="%T(pHead->zUuid)">
993993
@ <input type="submit" value="Attach...">
994
+ login_insert_csrf_secret();
994995
@ </form>
995996
}
996997
}
997998
@ </div>
998999
}
9991000
--- src/forum.c
+++ src/forum.c
@@ -989,10 +989,11 @@
989 }
990 if( g.perm.Admin || forumpost_is_owner(p/*not pHead*/->fpid, 0) ){
991 @ <form method="post" action="%R/attachadd">\
992 @ <input type="hidden" name="forumpost" value="%T(pHead->zUuid)">
993 @ <input type="submit" value="Attach...">
 
994 @ </form>
995 }
996 }
997 @ </div>
998 }
999
--- src/forum.c
+++ src/forum.c
@@ -989,10 +989,11 @@
989 }
990 if( g.perm.Admin || forumpost_is_owner(p/*not pHead*/->fpid, 0) ){
991 @ <form method="post" action="%R/attachadd">\
992 @ <input type="hidden" name="forumpost" value="%T(pHead->zUuid)">
993 @ <input type="submit" value="Attach...">
994 login_insert_csrf_secret();
995 @ </form>
996 }
997 }
998 @ </div>
999 }
1000

Keyboard Shortcuts

Open search /
Next entry (timeline) j
Previous entry (timeline) k
Open focused entry Enter
Show this help ?
Toggle theme Top nav button