Skip to content

Commit

Permalink
security: cross-site request forgery
Browse files Browse the repository at this point in the history
  • Loading branch information
HDVinnie committed Dec 14, 2021
1 parent 73eda44 commit 8356504
Show file tree
Hide file tree
Showing 2 changed files with 8 additions and 3 deletions.
9 changes: 7 additions & 2 deletions resources/views/user/user_modals.blade.php
Expand Up @@ -242,8 +242,13 @@
<div class="modal-body">
<div class="py-3">
<div class="text-center">
<a href="{{ route('user_delete', ['username' => $user->username]) }}"><input
class="btn btn-danger" type="submit" value="Yes, Delete"></a>
<form action="{{ route('user_delete', ['username' => $user->username]) }}" method="POST">
@csrf
@method('DELETE')
<button type="submit" class="btn btn-danger">
<i class="{{ config('other.font-awesome') }} fa-trash"></i> @lang('common.delete')
</button>
</form>
</div>
</div>
</div>
Expand Down
2 changes: 1 addition & 1 deletion routes/web.php
Expand Up @@ -894,7 +894,7 @@
Route::get('/{username}/settings', [App\Http\Controllers\Staff\UserController::class, 'settings'])->name('user_setting');
Route::post('/{username}/permissions', [App\Http\Controllers\Staff\UserController::class, 'permissions'])->name('user_permissions');
Route::post('/{username}/password', [App\Http\Controllers\Staff\UserController::class, 'password'])->name('user_password');
Route::get('/{username}/destroy', [App\Http\Controllers\Staff\UserController::class, 'destroy'])->name('user_delete');
Route::delete('/{username}/destroy', [App\Http\Controllers\Staff\UserController::class, 'destroy'])->name('user_delete');
Route::post('/{username}/warn', [App\Http\Controllers\Staff\UserController::class, 'warnUser'])->name('user_warn');
});

Expand Down

0 comments on commit 8356504

Please sign in to comment.