From 1a64c1c1db49b2deb28aeabf20dba0041488f83d Mon Sep 17 00:00:00 2001 From: Amit Gupta Date: Wed, 22 Jan 2020 21:37:22 +0530 Subject: [PATCH] Bug 22990: Add CSRF protection to boraccount, pay and suggestion Signed-off-by: David Cook Signed-off-by: Marcel de Rooy Test plan would have been nioe. Tested by changing MAX_AGE with suggestions. Signed-off-by: Tomas Cohen Arazi --- .../prog/en/modules/members/boraccount.tt | 11 +++++++---- .../intranet-tmpl/prog/en/modules/members/pay.tt | 1 + .../prog/en/modules/suggestion/suggestion.tt | 5 +++++ members/boraccount.pl | 15 ++++++++++----- members/pay.pl | 8 ++++++++ suggestion/suggestion.pl | 9 ++++++--- 6 files changed, 37 insertions(+), 12 deletions(-) diff --git a/koha-tmpl/intranet-tmpl/prog/en/modules/members/boraccount.tt b/koha-tmpl/intranet-tmpl/prog/en/modules/members/boraccount.tt index 1651563215..e964f5c3b4 100644 --- a/koha-tmpl/intranet-tmpl/prog/en/modules/members/boraccount.tt +++ b/koha-tmpl/intranet-tmpl/prog/en/modules/members/boraccount.tt @@ -55,7 +55,7 @@ [% INCLUDE 'members-toolbar.inc' %]

Account for [% INCLUDE 'patron-title.inc' %]

-
+
[% INCLUDE 'csrf-token.inc' %]
@@ -147,14 +147,14 @@ [% END %] Details [% IF account.is_debit && account.amountoutstanding > 0 %] - Pay + Pay [% END %] [% IF account.is_credit && account.status != 'VOID' %] - Void payment + Void payment [% END %] [% IF account.is_debit && account.amount == account.amountoutstanding && account.status != 'CANCELLED' && !(account.debit_type_code == 'PAYOUT') %]
- + [% INCLUDE 'csrf-token.inc' %]