Added new modules to help prevent Cross Site Request Forgery
[sdnc/oam.git] / admportal / views / user / list.ejs
index 4a4e909..ec650b0 100644 (file)
@@ -43,7 +43,7 @@
 <div class="container-fluid">
     <div class="actions" style="padding:15px 0px;">
        <% if(priv == 'A') { %>
-       <button class="btn btn-primary" data-toggle="modal" data-target="#newUserModal">Add User</button>
+       <button class="btn btn-primary" data-toggle="modal" data-target="#new_user">Add User</button>
        <% } %>
 
     </div>
                                <% } %>
                        </td> 
                        <% if(priv == 'A') { %>
-                       <td><form name="rowform">
-                               <input type="hidden" name="rfemail" id="rfemail" value="<%= row.email %>"</input>
+                       <td>
+                               <form name="rowform">
+                                       <button type="button" class="btn btn-default btn-xs"
+                                               onclick="updateRequest('<%=row.email %>', '<%=row.password %>', '<%=row.privilege %>');">Update</button>
+                                       <button type="button" class="btn btn-default btn-xs"
+                                               onclick="deleteRequest('<%=row.email %>');">Delete</button>
                                </form>
-                               <button type="button" class="btn btn-default btn-xs"
-                onclick="updateRequest('<%=row.email %>', '<%=row.password %>', '<%=row.privilege %>');">Update</button>
-                               <button type="button" class="btn btn-default btn-xs"
-                onclick="deleteRequest('<%=row.email %>');">Delete</button>
-            </td>
+                       </td>
                        <% } %>
                        </tr>
     <% }); }; %>
@@ -178,7 +178,7 @@ function updateRequest(email,password,privilege) {
        document.getElementById('uf_confirm_password').value = password;
        if ( privilege == "A" ){
                document.getElementById('uf_privilege').value = 'admin';
-       }else if (priv == "R"){
+       }else if (privilege == "R"){
                document.getElementById('uf_privilege').value = 'readonly';
        }else{
                document.getElementById('uf_privilege').value = 'admin';