Skip to content

Commit 7646755

Browse files
committed
remove XSRF input from templates
As of #177, we are now using Sec-Fetch-Site instead of xsrf tokens. Updates #178 Change-Id: Ia101a4a3005adb9118051b3416f5a64a4a45987d Signed-off-by: Will Norris <[email protected]>
1 parent a1ce1eb commit 7646755

File tree

4 files changed

+1
-5
lines changed

4 files changed

+1
-5
lines changed

flake.nix

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -39,7 +39,7 @@
3939
"-X tailscale.com/version.longStamp=${tsVersion}"
4040
"-X tailscale.com/version.shortStamp=${tsVersion}"
4141
];
42-
vendorHash = "sha256-RqKsIgwkCbIMQdCKtSHqW9eiZuNcZLCYeXFhPbgxjEU="; # SHA based on vendoring go.mod
42+
vendorHash = "sha256-PUobfmZyn5YtiFTpxTtjnPhqijR5tsONk4HNlIs1oNk="; # SHA based on vendoring go.mod
4343
};
4444
});
4545

tmpl/delete.html

Lines changed: 0 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -4,7 +4,6 @@ <h2 class="text-xl font-bold pb-2">Link {{go}}/{{.Short}} Deleted</h2>
44
<p class="py-4">Deleted this by mistake? You can recreate the same link below.</p>
55

66
<form method="POST" action="/">
7-
<input type="hidden" name="xsrf" value="{{ .XSRF }}" />
87
<div class="flex flex-wrap">
98
<div class="flex">
109
<label for=short class="flex my-2 px-2 items-center bg-gray-100 border border-r-0 border-gray-300 rounded-l-md text-gray-700">http://{{go}}/</label>

tmpl/detail.html

Lines changed: 0 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -3,7 +3,6 @@ <h2 class="text-xl font-bold pb-2">Link Details</h2>
33

44
{{ if .Editable }}
55
<form method="POST" action="/">
6-
<input type="hidden" name="xsrf" value="{{ .XSRF }}" />
76
<div class="flex flex-wrap">
87
<div class="flex">
98
<label for=short class="flex my-2 px-2 items-center bg-gray-100 border border-r-0 border-gray-300 rounded-l-md text-gray-700">http://{{go}}/</label>
@@ -33,7 +32,6 @@ <h2 class="text-xl font-bold pb-2">Link Details</h2>
3332
<h3 class="text-lg font-bold pb-2 pt-4 text-red-500">Danger Zone</h3>
3433

3534
<form method="POST" action="/.delete/{{.Link.Short}}">
36-
<input type="hidden" name="xsrf" value="{{ .XSRF }}" />
3735
<button type=submit class="py-2 px-4 my-2 rounded-md bg-red-500 border-red-500 text-white hover:bg-red-600 hover:border-red-600">Delete Link</button>
3836
</form>
3937

tmpl/home.html

Lines changed: 0 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -8,7 +8,6 @@ <h2 class="text-xl font-bold pb-2">Create a new link</h2>
88
<p class="">Did you mean <a class="text-blue-600 hover:underline" href="{{.}}">{{.}}</a> ? Create a {{go}} link for it now:</p>
99
{{ end }}
1010
<form method="POST" action="/" class="flex flex-wrap">
11-
<input type="hidden" name="xsrf" value="{{ .XSRF }}" />
1211
<div class="flex">
1312
<label for=short class="flex my-2 px-2 items-center bg-gray-100 border border-r-0 border-gray-300 rounded-l-md text-gray-700">http://{{go}}/</label>
1413
<input id=short name=short required type=text size=15 placeholder="shortname" value="{{.Short}}" pattern="\w[\w\-\.]*" title="Must start with letter or number; may contain letters, numbers, dashes, and periods."

0 commit comments

Comments
 (0)