mirror of
https://github.com/billz/raspap-webgui.git
synced 2025-03-01 10:31:47 +00:00
don't write the csrf token field to the output buffer
but return and echo it
This commit is contained in:
@@ -70,7 +70,7 @@ function ensureCSRFSessionToken()
|
||||
function CSRFToken()
|
||||
{
|
||||
$token = htmlspecialchars($_SESSION['csrf_token']);
|
||||
echo '<input id="csrf_token" type="hidden" name="csrf_token" value="' . $token . '">';
|
||||
return '<input id="csrf_token" type="hidden" name="csrf_token" value="' . $token . '">';
|
||||
}
|
||||
|
||||
/**
|
||||
|
Reference in New Issue
Block a user