changeset 257:6e7e84707e7d

Fix #106: CSRF verification failures on the deleting of checked PMs.
author Brian Neal <bgneal@gmail.com>
date Tue, 21 Sep 2010 01:16:02 +0000 (2010-09-21)
parents 9c82c7984884
children f9a9b4014d5b
files gpp/templates/messages/inbox.html gpp/templates/messages/outbox.html gpp/templates/messages/trash.html
diffstat 3 files changed, 3 insertions(+), 3 deletions(-) [+]
line wrap: on
line diff
--- a/gpp/templates/messages/inbox.html	Tue Sep 21 00:59:31 2010 +0000
+++ b/gpp/templates/messages/inbox.html	Tue Sep 21 01:16:02 2010 +0000
@@ -15,7 +15,7 @@
 {% endif %}
 {% if msgs %}
    <form action="{% url messages-delete_bulk %}" method="post" name="messages_box_form"
-      onsubmit="return messages_confirm_delete();">
+      onsubmit="return messages_confirm_delete();">{% csrf_token %}
    <table class="messages">
    <tr>
       <th>From</th>
--- a/gpp/templates/messages/outbox.html	Tue Sep 21 00:59:31 2010 +0000
+++ b/gpp/templates/messages/outbox.html	Tue Sep 21 01:16:02 2010 +0000
@@ -15,7 +15,7 @@
 {% endif %}
 {% if msgs %}
    <form action="{% url messages-delete_bulk %}" method="post" name="messages_box_form"
-      onsubmit="return messages_confirm_delete();">
+      onsubmit="return messages_confirm_delete();">{% csrf_token %}
    <table class="messages"> 
    <tr>
       <th>To</th>
--- a/gpp/templates/messages/trash.html	Tue Sep 21 00:59:31 2010 +0000
+++ b/gpp/templates/messages/trash.html	Tue Sep 21 01:16:02 2010 +0000
@@ -15,7 +15,7 @@
 {% endif %}
 {% if msgs %}
    <form action="{% url messages-undelete_bulk %}" method="post" name="messages_box_form"
-      onsubmit="return messages_confirm_undelete();">
+      onsubmit="return messages_confirm_undelete();">{% csrf_token %}
    <table class="messages">
    <tr>
       <th>From</th>