Skip to content
Snippets Groups Projects
Commit 1bfd3f60 authored by Regis Houssin's avatar Regis Houssin
Browse files

Fix: ajout d'un jeton aléatoire dans les requetes POST

parent d3621e45
No related branches found
No related tags found
No related merge requests found
...@@ -66,7 +66,7 @@ if ($_GET["msg"]) ...@@ -66,7 +66,7 @@ if ($_GET["msg"])
<!-- Dump of a server --> <!-- Dump of a server -->
<form method="post" action="export.php" name="dump"> <form method="post" action="export.php" name="dump">
<input type="hidden" name="token" value="<?php echo $_SESSION['newtoken'] ?>" /> <input type="hidden" name="token" value="<?php echo $_SESSION['newtoken']; ?>" />
<input type="hidden" name="export_type" value="server" /> <input type="hidden" name="export_type" value="server" />
......
...@@ -63,25 +63,22 @@ if ( $_SESSION['uid'] > 0 ) { ...@@ -63,25 +63,22 @@ if ( $_SESSION['uid'] > 0 ) {
<div class="principal_login"> <div class="principal_login">
<fieldset class="cadre_facturation"><legend class="titre1">Identification</legend> <fieldset class="cadre_facturation"><legend class="titre1">Identification</legend>
<form class="formulaire_login" id="frmLogin" method="post" action="index_verif.php"> <form class="formulaire_login" id="frmLogin" method="post" action="index_verif.php">
<input type="hidden" name="token" value="<?php echo $_SESSION['newtoken'] ?>" /> <input type="hidden" name="token" value="<?php echo $_SESSION['newtoken']; ?>" />
<table> <table>
<tr> <tr>
<td class="label1">Nom d'utilisateur</td> <td class="label1">Nom d'utilisateur</td>
<td><input name="txtUsername" class="texte_login" type="text" <td><input name="txtUsername" class="texte_login" type="text" value="<?php echo $_GET['user']; ?>" /></td>
value="<?php echo $_GET['user']; ?>" /></td>
</tr> </tr>
<tr> <tr>
<td class="label1">Mot de passe</td> <td class="label1">Mot de passe</td>
<td><input name="pwdPassword" class="texte_login" type="password" <td><input name="pwdPassword" class="texte_login" type="password" value="" /></td>
value="" /></td>
</tr> </tr>
</table> </table>
<span class="bouton_login"><input name="sbmtConnexion" type="submit" <span class="bouton_login"><input name="sbmtConnexion" type="submit" value="Connexion" /></span>
value="Connexion" /></span>
</form> </form>
</fieldset> </fieldset>
......
...@@ -20,6 +20,7 @@ Foundation, Inc., 59 Temple Place - Suite 330, Boston, MA 02111-1307, USA. ...@@ -20,6 +20,7 @@ Foundation, Inc., 59 Temple Place - Suite 330, Boston, MA 02111-1307, USA.
<!-- ========================= Cadre "Article" ============================= --> <!-- ========================= Cadre "Article" ============================= -->
<fieldset class="cadre_facturation"><legend class="titre1">Article</legend> <fieldset class="cadre_facturation"><legend class="titre1">Article</legend>
<form id="frmFacturation" class="formulaire1" method="post" action="facturation_verif.php"> <form id="frmFacturation" class="formulaire1" method="post" action="facturation_verif.php">
<input type="hidden" name="token" value="<?php echo $_SESSION['newtoken']; ?>" />
<input type="hidden" name="hdnSource" value="NULL" /> <input type="hidden" name="hdnSource" value="NULL" />
...@@ -103,6 +104,7 @@ Foundation, Inc., 59 Temple Place - Suite 330, Boston, MA 02111-1307, USA. ...@@ -103,6 +104,7 @@ Foundation, Inc., 59 Temple Place - Suite 330, Boston, MA 02111-1307, USA.
</form> </form>
<form id="frmQte" class="formulaire1" method="post" action="facturation_verif.php?action=ajout_article" onsubmit ="javascript: return verifSaisie();"> <form id="frmQte" class="formulaire1" method="post" action="facturation_verif.php?action=ajout_article" onsubmit ="javascript: return verifSaisie();">
<input type="hidden" name="token" value="<?php echo $_SESSION['newtoken']; ?>" />
<table> <table>
<tr><th class="label1">Quantit</th><th class="label1">Stock</th><th class="label1">Prix unitaire</th><th></th><th class="label1">Taux TVA</th><th class="label1">Remise (%)</th><th class="label1">Prix total</th></tr> <tr><th class="label1">Quantit</th><th class="label1">Stock</th><th class="label1">Prix unitaire</th><th></th><th class="label1">Taux TVA</th><th class="label1">Remise (%)</th><th class="label1">Prix total</th></tr>
<tr> <tr>
...@@ -145,6 +147,7 @@ Foundation, Inc., 59 Temple Place - Suite 330, Boston, MA 02111-1307, USA. ...@@ -145,6 +147,7 @@ Foundation, Inc., 59 Temple Place - Suite 330, Boston, MA 02111-1307, USA.
<!-- ========================= Cadre "Diffrence" ============================= --> <!-- ========================= Cadre "Diffrence" ============================= -->
<form id="frmDifference" class="formulaire1" method="post" onsubmit="javascript: return verifReglement()" action="validation_verif.php?action=valide_achat"> <form id="frmDifference" class="formulaire1" method="post" onsubmit="javascript: return verifReglement()" action="validation_verif.php?action=valide_achat">
<input type="hidden" name="token" value="<?php echo $_SESSION['newtoken']; ?>" />
<fieldset class="cadre_facturation"><legend class="titre1">Diffrence</legend> <fieldset class="cadre_facturation"><legend class="titre1">Diffrence</legend>
<table> <table>
<tr><th class="label1">Montant d</th><th class="label1">Encaiss</th><th class="label1">Rendu</th></tr> <tr><th class="label1">Montant d</th><th class="label1">Encaiss</th><th class="label1">Rendu</th></tr>
......
...@@ -62,6 +62,7 @@ Foundation, Inc., 59 Temple Place - Suite 330, Boston, MA 02111-1307, USA. ...@@ -62,6 +62,7 @@ Foundation, Inc., 59 Temple Place - Suite 330, Boston, MA 02111-1307, USA.
</table> </table>
<form id="frmValidation" class="formulaire2" method="post" action="validation_verif.php?action=valide_facture"> <form id="frmValidation" class="formulaire2" method="post" action="validation_verif.php?action=valide_facture">
<input type="hidden" name="token" value="<?php echo $_SESSION['newtoken']; ?>" />
<p class="note_label">Notes<br /><textarea class="textarea_note" name="txtaNotes"></textarea></p> <p class="note_label">Notes<br /><textarea class="textarea_note" name="txtaNotes"></textarea></p>
......
0% Loading or .
You are about to add 0 people to the discussion. Proceed with caution.
Please register or to comment