This commit is contained in:
Antonio de la Rosa 2016-05-25 13:50:45 +02:00
parent bef630ec1d
commit f5adbc376a
6 changed files with 39 additions and 54 deletions

View file

@ -76,8 +76,12 @@ class GenerateAdminClass:
post=self.model.select_a_row(getpostfiles.get['id'], [], True)
title_edit=I18n.lang('common', 'edit_new_item', 'Edit item')
if post==None:
post={}
if post==None or post==False:
if getpostfiles.get['id']=='0':
post={}
else:
return ""
form=show_form(post, edit_forms, self.t, False)

View file

@ -22,33 +22,37 @@ class GetPostFiles:
self.get=request.query.decode()
def obtain_post(self, required_post=[]):
def obtain_post(self, required_post=[], ignore_csrf_token=False):
self.post={}
self.post=request.forms.decode()
if len(required_post)==0:
required_post=self.post.keys()
for post in required_post:
self.post[post]=self.post.get(post, '')
s=get_session()
if 'csrf_token' in s:
self.post['csrf_token']=self.post.get('csrf_token', '')
if self.post['csrf_token']!=s['csrf_token'] and self.post['csrf_token'].strip()!="":
if ignore_csrf_token==False:
if 'csrf_token' in s:
raise NameError('Error: you need a valid csrf_token')
else:
#Clean csrf_token
del s['csrf_token']
self.post['csrf_token']=self.post.get('csrf_token', '')
if self.post['csrf_token']!=s['csrf_token'] and self.post['csrf_token'].strip()!="":
raise NameError('Error: you need a valid csrf_token')
else:
#Clean csrf_token
del s['csrf_token']
else:
raise NameError('Error: you don\'t send any valid csrf_token')
else:
raise NameError('Error: you don\'t send any valid csrf_token')
#Check post_token

View file

@ -287,7 +287,13 @@ class HeaderHTML:
self.css_local[module]=self.css_local.get(module, [])
self.css_local[module].append(css)
try:
self.css_local[module].index(css)
except:
self.css_local[module].append(css)
return ''
@ -297,7 +303,11 @@ class HeaderHTML:
self.js_local[module]=self.js_local.get(module, [])
self.js_local[module].append(js)
try:
self.js_local[module].index(js)
except:
self.js_local[module].append(js)
return ''