Update# CSRF check for email field

This commit is contained in:
Pellaeon Lin 2015-08-31 16:43:00 +08:00
parent afa7e75cc2
commit 14fcdc6643
2 changed files with 3 additions and 3 deletions

View File

@ -60,8 +60,6 @@ class RegisterController extends Controller {
} }
/** /**
* @NoAdminRequired
* @NoCSRFRequired
* @PublicPage * @PublicPage
*/ */
public function validateEmail() { public function validateEmail() {

View File

@ -14,10 +14,11 @@ if ($_['entered']): ?>
<li><?php print_unescaped($_['errormsg']); ?></li> <li><?php print_unescaped($_['errormsg']); ?></li>
</ul> </ul>
<p class="groupofone"> <p class="groupofone">
<input type="email" name="email" id="email" placeholder="<?php print_unescaped($l->t('Email')); ?>" value="" required autofocus /> <input type="email" name="email" id="email" placeholder="<?php print_unescaped($l->t('Email')); ?>" value="" required autofocus />
<label for="email" class="infield"><?php print_unescaped($l->t( 'Email' )); ?></label> <label for="email" class="infield"><?php print_unescaped($l->t( 'Email' )); ?></label>
<img id="email-icon" class="svg" src="<?php print_unescaped(image_path('', 'actions/mail.svg')); ?>" alt=""/> <img id="email-icon" class="svg" src="<?php print_unescaped(image_path('', 'actions/mail.svg')); ?>" alt=""/>
</p> </p>
<input type="hidden" name="requesttoken" value="<?php p($_['requesttoken']); ?>" />
<input type="submit" id="submit" value="<?php print_unescaped($l->t('Request verification link')); ?>" /> <input type="submit" id="submit" value="<?php print_unescaped($l->t('Request verification link')); ?>" />
</fieldset> </fieldset>
</form> </form>
@ -40,6 +41,7 @@ if ($_['entered']): ?>
<label for="email" class="infield"><?php print_unescaped($l->t('Email')); ?></label> <label for="email" class="infield"><?php print_unescaped($l->t('Email')); ?></label>
<img id="email-icon" class="svg" src="<?php print_unescaped(image_path('', 'actions/mail.svg')); ?>" alt=""/> <img id="email-icon" class="svg" src="<?php print_unescaped(image_path('', 'actions/mail.svg')); ?>" alt=""/>
</p> </p>
<input type="hidden" name="requesttoken" value="<?php p($_['requesttoken']); ?>" />
<input type="submit" id="submit" value="<?php print_unescaped($l->t('Request verification link')); ?>" /> <input type="submit" id="submit" value="<?php print_unescaped($l->t('Request verification link')); ?>" />
</fieldset> </fieldset>
</form> </form>