aboutsummaryrefslogtreecommitdiff
path: root/budget/templates
diff options
context:
space:
mode:
authorFrédéric Sureau <frederic.sureau@gmail.com>2012-01-28 01:35:04 +0100
committerFrédéric Sureau <frederic.sureau@gmail.com>2012-01-28 01:35:04 +0100
commita59465c9a5fa18be31f5698e07800387d0a8c4ff (patch)
tree085460e087e43c896515e96e4093851efd280187 /budget/templates
parent848e4a34ce6aea14baf7ade0463a7495d99b9294 (diff)
downloadihatemoney-mirror-a59465c9a5fa18be31f5698e07800387d0a8c4ff.zip
ihatemoney-mirror-a59465c9a5fa18be31f5698e07800387d0a8c4ff.tar.gz
ihatemoney-mirror-a59465c9a5fa18be31f5698e07800387d0a8c4ff.tar.bz2
Changed delete feature to only support POST method. Fix #21.
Diffstat (limited to 'budget/templates')
-rw-r--r--budget/templates/list_bills.html10
1 files changed, 7 insertions, 3 deletions
diff --git a/budget/templates/list_bills.html b/budget/templates/list_bills.html
index b698da6..7d3ff11 100644
--- a/budget/templates/list_bills.html
+++ b/budget/templates/list_bills.html
@@ -27,7 +27,7 @@
// ask for confirmation before removing an user
$('.action').each(function(){
$(this).hide();
- var link = $(this).find('a');
+ var link = $(this).find('button');
link.click(function(){
if ($(this).hasClass("confirm")){
return true;
@@ -83,9 +83,13 @@
{% if balance[member.id] > 0 %}+{% endif %}{{ balance[member.id] }}
</td>
{% if member.activated %}
- <td class="action delete"> <a href="{{ url_for(".remove_member", member_id=member.id) }}">{{ _("delete") }}</a></td>
+ <td class="action delete">
+ <form action="{{ url_for(".remove_member", member_id=member.id) }}" method="POST">
+ <button type="submit">{{ _("delete") }}</button></form></td>
{% else %}
- <td class="action reactivate"> <a href="{{ url_for(".reactivate", member_id=member.id) }}">{{ _("reactivate") }}</a></td>
+ <td class="action reactivate">
+ <form action="{{ url_for(".reactivate", member_id=member.id) }}" method="POST">
+ <button type="submit">{{ _("reactivate") }}</button></form></td>
{% endif %}
</tr>
{% endfor %}