Added new modules to help prevent Cross Site Request Forgery
[sdnc/oam.git] / admportal / views / partials / new_parameter.ejs
index b6d1f5b..4a2c0fe 100644 (file)
@@ -1,36 +1,37 @@
-   <div class="modal fade" id="new_parameter" tabindex="-1" role="dialog" 
+<div class="modal fade" id="new_parameter" tabindex="-1" role="dialog" 
                aria-labelledby="new_parameter_label" aria-hidden="true">
-      <div class="modal-dialog">
-        <div class="modal-content">
-          <div class="modal-header">
-            <button type="button" class="close" data-dismiss="modal" aria-hidden="true">&times;</button>
-            <h4 class="modal-title">Add Parameter</h4>
-          </div>
-          <div class="modal-body">
-            <form name="addForm" role="form" action="/admin/addParameter" method="POST">
-              <div class="form-group">
-                <label for="nf_name">*Name</label>
-                <input maxlength="100" type="text" class="form-control" name="nf_name" id="nf_name" placeholder="varchar(100)">
-              </div>
-              <div class="form-group">
-                <label for="nf_value">*Value</label>
-                <input maxlength="100" type="text" class="form-control" name="nf_value" id="nf_value" placeholder="varchar(100)">
-              </div>
-              <div class="form-group">
-                <label for="nf_category">Category</label>
-                <input maxlength="24" type="text" class="form-control" name="nf_category" id="nf_category" placeholder="varchar(24)">
-              </div>
-              <div class="form-group">
-                <label for="nf_memo">Memo</label>
-                <input maxlength="128" type="text" class="form-control" name="nf_memo" id="nf_memo" placeholder="varchar(128)">
-              </div>
-                         <div class="form-group">
-                  <input type="hidden" name="nf_action" id="nf_action">
-                  <button type="button" class="btn btn-primary" onclick="submitParam(this.form);">Submit</button>
-                  <button type="button" class="btn btn-default" data-dismiss="modal">Cancel</button>
-              </div>
-           </form>
-          </div>
-      </div>
-    </div>
-  </div>
+       <div class="modal-dialog">
+               <div class="modal-content">
+                       <div class="modal-header">
+                               <button type="button" class="close" data-dismiss="modal" aria-hidden="true">&times;</button>
+                               <h4 class="modal-title">Add Parameter</h4>
+                       </div>
+                       <div class="modal-body">
+                               <form name="addForm" role="form" action="/admin/addParameter" method="POST">
+                                       <div class="form-group">
+                                               <label for="nf_name">*Name</label>
+                                               <input maxlength="100" type="text" class="form-control" name="nf_name" id="nf_name" placeholder="varchar(100)" />
+                                       </div>
+                                       <div class="form-group">
+                                               <label for="nf_value">*Value</label>
+                                               <input maxlength="100" type="text" class="form-control" name="nf_value" id="nf_value" placeholder="varchar(100)" />
+                                       </div>
+                                       <div class="form-group">
+                                               <label for="nf_category">Category</label>
+                                               <input maxlength="24" type="text" class="form-control" name="nf_category" id="nf_category" placeholder="varchar(24)" />
+                                       </div>
+                                       <div class="form-group">
+                                               <label for="nf_memo">Memo</label>
+                                               <input maxlength="128" type="text" class="form-control" name="nf_memo" id="nf_memo" placeholder="varchar(128)" />
+                                       </div>
+                                       <div class="form-group">
+                                               <input type="hidden" name="_csrf" value="<%= privilege.csrfToken %>" />
+               <input type="hidden" name="nf_action" id="nf_action">
+               <button type="button" class="btn btn-primary" onclick="submitParam(this.form);">Submit</button>
+               <button type="button" class="btn btn-default" data-dismiss="modal">Cancel</button>
+               </div>
+        </form>
+                       </div>
+               </div>
+       </div>
+</div>