CSRF antiforgery fixes

This commit is contained in:
Hamid Reza Mohammadi 2026-09-27 14:03:38 +03:30
parent b6552e3e43
commit 7a722455ec
128 changed files with 109 additions and 83 deletions

View File

@ -19,6 +19,7 @@
<div class="up-card">
<h2 class="up-card__title">آگاهی جدید</h2>
<form method="post" enctype="multipart/form-data" class="up-form">
@Html.AntiForgeryToken()
<div class="up-field">
<label for="Upload_Image">تصویر</label>
<input type="file" asp-for="Upload.Image" />

View File

@ -12,7 +12,6 @@ using System.Threading.Tasks;
namespace GanjooRazor.Areas.Admin.Pages
{
[IgnoreAntiforgeryToken(Order = 1001)]
public class BannersModel : PageModel
{
/// <summary>

View File

@ -28,6 +28,7 @@ else
<tr>
<td>
<form method="post" action="/Admin/CatDel?id=@Model.Cat.Cat.Id">
@Html.AntiForgeryToken()
<input type="submit" value="بله" />
</form>
</td>

View File

@ -9,7 +9,6 @@ using System.Threading.Tasks;
namespace GanjooRazor.Areas.Admin.Pages
{
[IgnoreAntiforgeryToken(Order = 1001)]
public class CatDelModel : PageModel
{
/// <summary>

View File

@ -93,6 +93,7 @@ else
<div class="up-field">
<label for="DestCatId">مشابه‌یابی در بخش</label>
<form method="post" action="/Admin/CatTrans?Handler=FindDuplicates&id=@Model.CatId" class="up-form-actions">
@Html.AntiForgeryToken()
<input asp-for="DestCatId" style="flex:1;" />
<input type="submit" value="شروع مشابه‌یابی" class="up-btn up-btn--ghost" />
</form>
@ -103,6 +104,7 @@ else
<div class="up-field">
<label for="DestCatId">نهایی‌سازی انتقال به بخش</label>
<form method="post" action="/Admin/CatTrans?Handler=Finalize&id=@Model.CatId" class="up-form-actions">
@Html.AntiForgeryToken()
<input asp-for="DestCatId" style="flex:1;" />
<input type="submit" value="نهایی سازی" class="up-btn up-btn--success" />
</form>

View File

@ -15,7 +15,6 @@ using RMuseum.Models.Ganjoor.ViewModels;
namespace GanjooRazor.Areas.Admin.Pages
{
[IgnoreAntiforgeryToken(Order = 1001)]
public class CatTransModel : PageModel
{
/// <summary>

View File

@ -484,6 +484,7 @@
}
<form method="post">
@Html.AntiForgeryToken()
<table>
<tr>
<td>
@ -643,6 +644,7 @@
</table>
<form method="post" action="?Handler=Numbering&url=@Model.Cat.Cat.FullUrl">
@Html.AntiForgeryToken()
<table>
<tr>
<td>
@ -678,6 +680,7 @@
<h2>ابرداده‌های دیگر بخش</h2>
<form method="post" action="?Handler=UpdateCatMeta&url=@Model.Cat.Cat.FullUrl">
@Html.AntiForgeryToken()
<table>
<tr>
<td>
@ -725,6 +728,7 @@
<td>بارگذاری پایگاه داده‌ها شامل یک دسته‌بندی از اشعار:</td>
<td>
<form method="post" enctype="multipart/form-data" action="/Admin/CatUtils?Handler=UploadDb&url=@Model.Cat.Cat.FullUrl">
@Html.AntiForgeryToken()
<input type="file" asp-for="SQLiteDb" />
<input type="submit" value="بارگذاری" class="up-btn up-btn--success" />
</form>

View File

@ -14,7 +14,6 @@ using System.Threading.Tasks;
namespace GanjooRazor.Areas.Admin.Pages
{
[IgnoreAntiforgeryToken(Order = 1001)]
public class CatUtilsModel : GanjoorPageModelBase
{
/// <summary>

View File

@ -15,6 +15,7 @@
@if (Model.Donation != null)
{
<form method="post">
@Html.AntiForgeryToken()
<table>
<tr>

View File

@ -9,7 +9,6 @@ using RMuseum.Models.Accounting.ViewModels;
namespace GanjooRazor.Areas.Admin.Pages
{
[IgnoreAntiforgeryToken(Order = 1001)]
public class DonationEditModel : PageModel
{
/// <summary>

View File

@ -27,6 +27,7 @@
<div class="up-card">
<h2 class="up-card__title">کمک مالی جدید</h2>
<form method="post" class="up-form">
@Html.AntiForgeryToken()
<div class="up-field">
<label asp-for="Donation.RecordDate">تاریخ</label>
<input type="date" asp-for="Donation.RecordDate" />

View File

@ -13,7 +13,6 @@ using RMuseum.Utils;
namespace GanjooRazor.Areas.Admin.Pages
{
[IgnoreAntiforgeryToken(Order = 1001)]
public class DonationsModel : PageModel
{
/// <summary>

View File

@ -230,6 +230,7 @@
</script>
<div class="up-card">
<form method="post" class="up-form">
@Html.AntiForgeryToken()
<p>
بیت مرجع از <a href="/?p=@Model.GanjoorQuotedPoem.PoemId">شعر</a>:
<input type="hidden" asp-for="GanjoorQuotedPoem.Id" />

View File

@ -15,7 +15,6 @@ using System.Net;
namespace GanjooRazor.Areas.Admin.Pages
{
[IgnoreAntiforgeryToken(Order = 1001)]
public class EditQuotedModel : PageModel
{
public string LastMessage { get; set; }

View File

@ -12,6 +12,7 @@
@if (Model.Expense != null)
{
<form method="post">
@Html.AntiForgeryToken()
<table>
<tr>

View File

@ -10,7 +10,6 @@ using RMuseum.Models.Accounting.ViewModels;
namespace GanjooRazor.Areas.Admin.Pages
{
[IgnoreAntiforgeryToken(Order = 1001)]
public class ExpenseEditModel : PageModel
{
/// <summary>

View File

@ -17,6 +17,7 @@
<div class="up-card">
<h2 class="up-card__title">هزینهٔ جدید</h2>
<form method="post" class="up-form">
@Html.AntiForgeryToken()
<div class="up-field">
<label asp-for="Expense.ExpenseDate">تاریخ</label>
<input type="date" asp-for="Expense.ExpenseDate" />

View File

@ -10,7 +10,6 @@ using RMuseum.Models.Accounting;
namespace GanjooRazor.Areas.Admin.Pages
{
[IgnoreAntiforgeryToken(Order = 1001)]
public class ExpensesModel : PageModel
{
/// <summary>

View File

@ -33,6 +33,7 @@ else
<tr>
<td>
<form method="post">
@Html.AntiForgeryToken()
<input type="hidden" asp-for="UserCauseViewModel.UserId" />
<table>
<tr>

View File

@ -10,7 +10,6 @@ using RSecurityBackend.Models.Auth.ViewModels;
namespace GanjooRazor.Areas.Admin.Pages
{
[IgnoreAntiforgeryToken(Order = 1001)]
public class KickoutUserModel : PageModel
{
public PublicRAppUser UserInfo { get; set; }

View File

@ -28,6 +28,7 @@
<div class="up-card">
<h2 class="up-card__title">خاستگاه جدید</h2>
<form method="post" class="up-form">
@Html.AntiForgeryToken()
<div class="up-field">
<label for="Location_Name">نام</label>
<input asp-for="Location.Name" />

View File

@ -8,7 +8,6 @@ using System.Text;
using System.Threading.Tasks;
namespace GanjooRazor.Areas.Admin.Pages
{
[IgnoreAntiforgeryToken(Order = 1001)]
public class LocationsModel : PageModel
{
public string LastMessage { get; set; }

View File

@ -9,7 +9,6 @@ using RSecurityBackend.Models.Generic.Db;
namespace GanjooRazor.Areas.Admin.Pages
{
[IgnoreAntiforgeryToken(Order = 1001)]
public class LongRunningJobsModel : PageModel
{
public RLongRunningJobStatus[] Jobs { get; set; }

View File

@ -41,6 +41,7 @@
<div class="up-card">
<form method="post" class="up-form">
@Html.AntiForgeryToken()
<div class="up-field">
<label>شناسهٔ صفحه</label>
<div class="up-field-static"><a href="/?p=@Request.Query["id"]">@Request.Query["id"]</a></div>
@ -181,6 +182,7 @@
<div class="up-card">
<form action="?Handler=GenerateCatPage&id=@Model.PageInformation.Id" method="post" class="up-form">
@Html.AntiForgeryToken()
<div class="up-field">
<label asp-for="GanjoorTOC">تولید فهرست</label>
<select asp-for="GanjoorTOC">

View File

@ -15,7 +15,6 @@ using System.Threading.Tasks;
namespace GanjooRazor.Areas.Admin.Pages
{
[IgnoreAntiforgeryToken(Order = 1001)]
public class ModifyPageModel : PageModel
{

View File

@ -28,6 +28,7 @@ else
<tr>
<td>
<form method="post" action="/Admin/PageDel?id=@Model.PageInformation.Id">
@Html.AntiForgeryToken()
<input type="submit" value="بله" />
</form>
</td>

View File

@ -9,7 +9,6 @@ using RMuseum.Models.Ganjoor.ViewModels;
namespace GanjooRazor.Areas.Admin.Pages
{
[IgnoreAntiforgeryToken(Order = 1001)]
public class PageDelModel : PageModel
{
/// <summary>

View File

@ -17,6 +17,7 @@
else
{
<form method="post" action="/Admin/Poet/?Handler=EditPoet&id=@Model.Poet.Id">
@Html.AntiForgeryToken()
<table>
<tr>
@ -111,6 +112,7 @@ else
<td>تصویر جدید:</td>
<td>
<form method="post" enctype="multipart/form-data" action="/Admin/Poet/?Handler=UploadImage&id=@Model.Poet.Id">
@Html.AntiForgeryToken()
<input type="file" asp-for="Image" />
<input type="submit" value="بارگذاری" />
</form>
@ -132,6 +134,7 @@ else
<td>بارگذاری پایگاه داده‌ها:</td>
<td>
<form method="post" enctype="multipart/form-data" action="/Admin/Poet/?Handler=UploadDb&id=@Model.Poet.Id">
@Html.AntiForgeryToken()
<input type="file" asp-for="SQLiteDb" />
<input type="submit" value="بارگذاری" />
</form>
@ -144,6 +147,7 @@ else
<td>تصحیح از طریق پایگاه داده‌ها:</td>
<td>
<form method="post" enctype="multipart/form-data" action="/Admin/Poet/?Handler=UploadCorrectionDb&id=@Model.Poet.Id">
@Html.AntiForgeryToken()
<input type="file" asp-for="CorrecionDbModel.Db" />
<input asp-for="CorrecionDbModel.Note" size="50" />
<input type="submit" value="بارگذاری" />

View File

@ -15,7 +15,6 @@ using RMuseum.Services.Implementation.ImportedFromDesktopGanjoor;
namespace GanjooRazor.Areas.Admin.Pages
{
[IgnoreAntiforgeryToken(Order = 1001)]
public class PoetModel : PageModel
{
/// <summary>

View File

@ -28,6 +28,7 @@ else
<tr>
<td>
<form method="post">
@Html.AntiForgeryToken()
<input type="submit" value="بله" />
</form>
</td>

View File

@ -10,7 +10,6 @@ using RMuseum.Models.Ganjoor.ViewModels;
namespace GanjooRazor.Areas.Admin.Pages
{
[IgnoreAntiforgeryToken(Order = 1001)]
public class PoetDelModel : PageModel
{
/// <summary>

View File

@ -12,7 +12,6 @@ using System.Threading.Tasks;
namespace GanjooRazor.Areas.Admin.Pages
{
[IgnoreAntiforgeryToken(Order = 1001)]
public class PoetsModel : PageModel
{
/// <summary>

View File

@ -13,7 +13,6 @@ namespace GanjooRazor.Areas.Admin.Pages
/// (e.g. jsDelivr) — mainly meant to make setting up a fork or local dev copy easier than the
/// old per-poet SQLite import.
/// </summary>
[IgnoreAntiforgeryToken(Order = 1001)]
public class PublicDataImportModel : PageModel
{
/// <summary>

View File

@ -174,6 +174,7 @@
<div class="up-form-actions">
<a role="button" id="moderatecorrections" class="up-btn up-btn--success" onclick="moderateCorrections(@Model.Correction.Id)">بررسی</a>
<form method="post">
@Html.AntiForgeryToken()
<button type="submit" name="next" id="next" class="up-btn up-btn--ghost">بعدی</button>
</form>
</div>

View File

@ -17,7 +17,6 @@ using GanjooRazor.Models;
namespace GanjooRazor.Areas.Admin.Pages
{
[IgnoreAntiforgeryToken(Order = 1001)]
public class ReviewCatEditsModel : PageModel
{
/// <summary>

View File

@ -234,6 +234,7 @@ else
</td>
<td>
<form method="post">
@Html.AntiForgeryToken()
<button type="submit" name="next" id="next" class="up-btn up-btn--ghost up-btn--block">بعدی</button>
</form>
</td>
@ -937,7 +938,6 @@ else
<input type="text" id="geotag@(geoIndex)_latitude" name="geotag@(geoIndex)_latitude" value="@geoTag.SuggestedLatitude" size="12" />
<label for="geotag@(geoIndex)_longitude">طول جغرافیایی اصلاح‌شده:</label>
<input type="text" id="geotag@(geoIndex)_longitude" name="geotag@(geoIndex)_longitude" value="@geoTag.SuggestedLongitude" size="12" />
<a role="button" class="up-btn up-btn--ghost up-btn--sm" onclick="viewLocation($('#geotag@(geoIndex)_latitude').val(), $('#geotag@(geoIndex)_longitude').val())">🗺️ مشاهده در نقشه</a>
</div>
}
</td>
@ -946,7 +946,7 @@ else
<tr>
<td colspan="2">
<div class="up-radio-option">
<input type="radio" id="geotag@(geoIndex)_review_result_Approved" name="geotag@(geoIndex)_review_result" class="radio-approved" value="@RMuseum.Models.Ganjoor.CorrectionReviewResult.Approved" checked="checked">
<input type="radio" id="geotag@(geoIndex)_review_result_Approved" name="geotag@(geoIndex)_review_result" class="radio-approved" value="@RMuseum.Models.Ganjoor.CorrectionReviewResult.Approved">
<label for="geotag@(geoIndex)_review_result_Approved">@RMuseum.Services.Implementation.CorrectionReviewResultConvertor.GetString(RMuseum.Models.Ganjoor.CorrectionReviewResult.Approved)</label>
</div>
<div class="up-radio-option">
@ -958,7 +958,7 @@ else
<label for="geotag@(geoIndex)_review_result_RejectedBecauseUnnecessaryChange">تغییر سلیقه‌ای یا بی دلیل است</label>
</div>
<div class="up-radio-option">
<input type="radio" id="geotag@(geoIndex)_review_result_Rejected" name="geotag@(geoIndex)_review_result" class="radio-rejected" value="@RMuseum.Models.Ganjoor.CorrectionReviewResult.Rejected">
<input type="radio" id="geotag@(geoIndex)_review_result_Rejected" name="geotag@(geoIndex)_review_result" class="radio-rejected" value="@RMuseum.Models.Ganjoor.CorrectionReviewResult.Rejected" checked="checked">
<label for="geotag@(geoIndex)_review_result_Rejected">@RMuseum.Services.Implementation.CorrectionReviewResultConvertor.GetString(RMuseum.Models.Ganjoor.CorrectionReviewResult.Rejected)</label>
</div>
<input type="text" id="geotag@(geoIndex)_review_note" name="geotag@(geoIndex)_review_note" value="" size="50" />

View File

@ -17,7 +17,6 @@ using RSecurityBackend.Models.Generic;
namespace GanjooRazor.Areas.Admin.Pages
{
[IgnoreAntiforgeryToken(Order = 1001)]
public class ReviewEditsModel : PageModel
{
/// <summary>

View File

@ -518,6 +518,7 @@ else
<div class="up-form-actions">
<a role="button" id="moderatecorrections" class="up-btn up-btn--success" onclick="moderateSectionCorrections(@Model.Correction.Id, @Model.Verses.Count)">بررسی</a>
<form method="post">
@Html.AntiForgeryToken()
<button type="submit" name="next" id="next" class="up-btn up-btn--ghost">بعدی</button>
</form>
</div>

View File

@ -15,7 +15,6 @@ using System.Collections.Generic;
namespace GanjooRazor.Areas.Admin.Pages
{
[IgnoreAntiforgeryToken(Order = 1001)]
public class ReviewPartEditsModel : PageModel
{
/// <summary>

View File

@ -28,6 +28,7 @@ else
</div>
<form method="post" class="up-form">
@Html.AntiForgeryToken()
<input type="hidden" asp-for="ModerationModel.Id" />
<div class="up-field">
<label asp-for="ModerationModel.Approved">تأیید می‌شود؟</label>

View File

@ -16,7 +16,6 @@ using RMuseum.Models.Auth.ViewModel;
namespace GanjooRazor.Areas.Admin.Pages
{
[IgnoreAntiforgeryToken(Order = 1001)]
public class ReviewQuotedsModel : PageModel
{
/// <summary>

View File

@ -11,7 +11,6 @@ using System.Threading.Tasks;
namespace GanjooRazor.Areas.Admin.Pages
{
[IgnoreAntiforgeryToken(Order = 1001)]
public class RolesModel : PageModel
{
/// <summary>

View File

@ -28,6 +28,7 @@ else
<tr>
<td>
<form method="post">
@Html.AntiForgeryToken()
<input type="submit" value="بله" />
</form>
</td>

View File

@ -8,7 +8,6 @@ using System.Threading.Tasks;
namespace GanjooRazor.Areas.Admin.Pages
{
[IgnoreAntiforgeryToken(Order = 1001)]
public class SectionDelModel : PageModel
{
/// <summary>

View File

@ -10,6 +10,7 @@
@if (ViewData.ContainsKey("ganjoor-songrevu"))
{
<form method="post">
@Html.AntiForgeryToken()
<input asp-for="@Model.Code" type="hidden" />

View File

@ -12,7 +12,6 @@ using Newtonsoft.Json.Linq;
namespace GanjooRazor.Areas.Admin.Pages
{
[IgnoreAntiforgeryToken(Order = 1001)]
public class SpotifyCallbackModel : PageModel
{
public SpotifyCallbackModel(IHttpClientFactory clientFactory, IConfiguration configuration)

View File

@ -10,7 +10,6 @@ using System.Threading.Tasks;
namespace GanjooRazor.Areas.Admin.Pages
{
[IgnoreAntiforgeryToken(Order = 1001)]
public class TransferMeterModel : PageModel
{
/// <summary>

View File

@ -15,7 +15,6 @@ using System.Threading.Tasks;
namespace GanjooRazor.Areas.Admin.Pages
{
[IgnoreAntiforgeryToken(Order = 1001)]
public class UsersModel : PageModel
{
/// <summary>

View File

@ -17,6 +17,7 @@
<div class="up-card">
<form method="post" class="up-form">
@Html.AntiForgeryToken()
<div class="up-field">
<label asp-for="PoemMusicTrackViewModel.PoemId">شناسهٔ شعر</label>
<input asp-for="PoemMusicTrackViewModel.PoemId" />

View File

@ -9,7 +9,6 @@ using RMuseum.Models.Ganjoor.ViewModels;
namespace GanjooRazor.Areas.User.Pages
{
[IgnoreAntiforgeryToken(Order = 1001)]
public class AddSongModel : PageModel
{

View File

@ -9,7 +9,6 @@ using RMuseum.Models.Ganjoor;
namespace GanjooRazor.Areas.User.Pages
{
[IgnoreAntiforgeryToken(Order = 1001)]
public class AllPoemSectionsModel : PageModel
{
/// <summary>

View File

@ -16,7 +16,6 @@ using System.Threading.Tasks;
namespace GanjooRazor.Areas.User.Pages
{
[IgnoreAntiforgeryToken(Order = 1001)]
public class AwaitingCommentsModel : PageModel
{
/// <summary>

View File

@ -93,6 +93,7 @@
<div class="up-card">
<form method="post" class="up-form">
@Html.AntiForgeryToken()
@if (Model.PageInformation != null)
{
<p><a role="button" target="_blank" href="@Model.PageInformation.FullUrl" class="up-btn up-btn--ghost">@Model.PageInformation.FullTitle</a></p>

View File

@ -12,7 +12,6 @@ using RMuseum.Utils;
namespace GanjooRazor.Areas.User.Pages
{
[IgnoreAntiforgeryToken(Order = 1001)]
public class CatEditorModel : PageModel
{
/// <summary>

View File

@ -14,7 +14,6 @@ using System.Linq;
namespace GanjooRazor.Areas.User.Pages
{
[IgnoreAntiforgeryToken(Order = 1001)]
public class CatEditsModel : PageModel
{
/// <summary>

View File

@ -12,7 +12,6 @@ using System.Threading.Tasks;
namespace GanjooRazor.Areas.User.Pages
{
[IgnoreAntiforgeryToken(Order = 1001)]
public class DeleteAccountModel : PageModel
{
/// <summary>

View File

@ -14,7 +14,6 @@ using RMuseum.Models.Ganjoor.ViewModels;
namespace GanjooRazor.Areas.User.Pages
{
[IgnoreAntiforgeryToken(Order = 1001)]
public class EditorModel : PageModel
{
/// <summary>

View File

@ -18,7 +18,6 @@ using RSecurityBackend.Models.Generic;
namespace GanjooRazor.Areas.User.Pages
{
[IgnoreAntiforgeryToken(Order = 1001)]
public class EditsModel : PageModel
{
/// <summary>

View File

@ -17,6 +17,7 @@
else
{
<form method="post">
@Html.AntiForgeryToken()
<table>
<tr>
<td>

View File

@ -10,7 +10,6 @@ using System.Threading.Tasks;
namespace GanjooRazor.Areas.User.Pages
{
[IgnoreAntiforgeryToken(Order = 1001)]
public class FAQCatEditModel : PageModel
{
[BindProperty]

View File

@ -16,6 +16,7 @@
else
{
<form method="post">
@Html.AntiForgeryToken()
<table class="width-100per max-width-none">
<tr>
<td>

View File

@ -10,7 +10,6 @@ using System.Threading.Tasks;
namespace GanjooRazor.Areas.User.Pages
{
[IgnoreAntiforgeryToken(Order = 1001)]
public class FAQItemEditModel : PageModel
{
[BindProperty]

View File

@ -10,7 +10,6 @@ using System.Threading.Tasks;
namespace GanjooRazor.Areas.User.Pages
{
[IgnoreAntiforgeryToken(Order = 1001)]
public class FAQItemsModel : PageModel
{
public string LastMessage { get; set; }

View File

@ -39,6 +39,7 @@ else
</div>
<form method="post" class="up-form">
@Html.AntiForgeryToken()
<input type="hidden" asp-for="ImageLinkFinalizeModel.Id" />
<div class="up-field">
<label asp-for="ImageLinkFinalizeModel.DisplayOnPage"></label>

View File

@ -11,7 +11,6 @@ using RSecurityBackend.Models.Generic;
namespace GanjooRazor.Areas.User.Pages
{
[IgnoreAntiforgeryToken(Order = 1001)]
public class FinalizeImagesModel : PageModel
{
/// <summary>

View File

@ -18,7 +18,6 @@ using System.Threading.Tasks;
namespace GanjooRazor.Areas.User.Pages
{
[IgnoreAntiforgeryToken(Order = 1001)]
public class HistoryModel : PageModel
{

View File

@ -10,7 +10,6 @@ using System.Threading.Tasks;
namespace GanjooRazor.Areas.Panel.Pages
{
[IgnoreAntiforgeryToken(Order = 1001)]
public class IndexModel : PageModel
{
/// <summary>

View File

@ -16,6 +16,7 @@
else
{
<form method="post">
@Html.AntiForgeryToken()
<table>
<tr>
<td>

View File

@ -10,7 +10,6 @@ using RMuseum.Models.Ganjoor;
namespace GanjooRazor.Areas.User.Pages
{
[IgnoreAntiforgeryToken(Order = 1001)]
public class LanguageEditModel : PageModel
{
[BindProperty]

View File

@ -19,6 +19,7 @@ else
<div class="up-card">
<h2 class="up-card__title">زبان جدید</h2>
<form method="post" class="up-form">
@Html.AntiForgeryToken()
<div class="up-field">
<label for="Language_Name">نام</label>
<input asp-for="Language.Name" />

View File

@ -10,7 +10,6 @@ using RMuseum.Models.Ganjoor;
namespace GanjooRazor.Areas.User.Pages
{
[IgnoreAntiforgeryToken(Order = 1001)]
public class LanguagesModel : PageModel
{
public string LastMessage { get; set; }

View File

@ -129,6 +129,7 @@ else
<span onclick="document.getElementById('bookmark-note-dialog').style.display='none'"
class="close" title="بستن">&times;</span>
<form class="modal-content animate" method="post" id="editnoteform">
@Html.AntiForgeryToken()
<table class="max-width-100per width-100per">
<tr>
<td>

View File

@ -17,7 +17,6 @@ using RSecurityBackend.Models.Generic;
namespace GanjooRazor.Areas.User.Pages
{
[IgnoreAntiforgeryToken(Order = 1001)]
public class MyBookmarksModel : PageModel
{
/// <summary>

View File

@ -101,6 +101,7 @@ else
<span onclick="document.getElementById('id02').style.display='none'"
class="close" title="بستن">&times;</span>
<form class="modal-content animate" method="post" id="editcommentform" action="?handler=EditComment">
@Html.AntiForgeryToken()
<table style="max-width:100%; width:100%; margin:0">
<tr>
<td>

View File

@ -17,7 +17,6 @@ using RSecurityBackend.Models.Generic;
namespace GanjooRazor.Areas.User.Pages
{
[IgnoreAntiforgeryToken(Order = 1001)]
public class MyCommentsModel : PageModel
{
/// <summary>

View File

@ -20,7 +20,6 @@ namespace GanjooRazor.Areas.User.Pages
/// this list and kill a session they don't recognize (a lost/stolen device, a shared computer
/// they forgot to log out of, ...) whenever they suspect something.
/// </summary>
[IgnoreAntiforgeryToken(Order = 1001)]
public class MySessionsModel : GanjoorPageModelBase
{
/// <summary>

View File

@ -16,7 +16,6 @@ using RSecurityBackend.Models.Notification.ViewModels;
namespace GanjooRazor.Areas.User.Pages
{
[IgnoreAntiforgeryToken(Order = 1001)]
public class NotificationsModel : PageModel
{
/// <summary>

View File

@ -16,7 +16,6 @@ using RSecurityBackend.Models.Generic;
namespace GanjooRazor.Areas.User.Pages
{
[IgnoreAntiforgeryToken(Order = 1001)]
public class PoemCorrectionsHistoryModel : PageModel
{

View File

@ -16,7 +16,6 @@ using System.Text;
namespace GanjooRazor.Areas.User.Pages
{
[IgnoreAntiforgeryToken(Order = 1001)]
public class ReportedCommentsModel : PageModel
{
/// <summary>

View File

@ -27,6 +27,7 @@ else
{
<div class="up-card">
<form method="post" class="up-form">
@Html.AntiForgeryToken()
<div class="up-field">
<label>شعر</label>
<div>

View File

@ -12,7 +12,6 @@ using System.Threading.Tasks;
namespace GanjooRazor.Areas.User.Pages
{
[IgnoreAntiforgeryToken(Order = 1001)]
public class ReviewSongsModel : PageModel
{

View File

@ -14,7 +14,6 @@ using RMuseum.Models.Ganjoor.ViewModels;
namespace GanjooRazor.Areas.User.Pages
{
[IgnoreAntiforgeryToken(Order = 1001)]
public class SectionModel : PageModel
{
/// <summary>

View File

@ -15,7 +15,6 @@ using RSecurityBackend.Models.Generic;
namespace GanjooRazor.Areas.User.Pages
{
[IgnoreAntiforgeryToken(Order = 1001)]
public class SectionEditsModel : PageModel
{
/// <summary>

View File

@ -144,6 +144,7 @@
</div>
<div class="up-card">
<form method="post" class="up-form">
@Html.AntiForgeryToken()
<div class="up-alert up-alert--info">
<p class="up-mt-0">از فهرست زیر بیتی را که نقل قول در آن رخ داده مشخص کنید.</p>
</div>

View File

@ -15,7 +15,6 @@ using System.Net;
namespace GanjooRazor.Areas.User.Pages
{
[IgnoreAntiforgeryToken(Order = 1001)]
public class SuggestQuotedModel : PageModel
{
public string LastMessage { get; set; }

View File

@ -17,6 +17,7 @@ else
{
<div class="up-card">
<form method="post" class="up-form">
@Html.AntiForgeryToken()
<div class="up-field">
<label>سخنور</label>
<div>

View File

@ -11,7 +11,6 @@ using System.Threading.Tasks;
namespace GanjooRazor.Areas.User.Pages
{
[IgnoreAntiforgeryToken(Order = 1001)]
public class SuggestedPoetPhotosModel : PageModel
{
/// <summary>

View File

@ -17,6 +17,7 @@ else
{
<div class="up-card">
<form method="post" class="up-form">
@Html.AntiForgeryToken()
<div class="up-field">
<label>سخنور</label>
<div>

View File

@ -11,7 +11,6 @@ using System.Threading.Tasks;
namespace GanjooRazor.Areas.User.Pages
{
[IgnoreAntiforgeryToken(Order = 1001)]
public class SuggestedPoetSpecLinesModel : PageModel
{
/// <summary>

View File

@ -15,7 +15,6 @@ using System.Threading.Tasks;
namespace GanjooRazor.Areas.User.Pages
{
[IgnoreAntiforgeryToken(Order = 1001)]
public class UpVotedRecitationsModel : PageModel
{
/// <summary>

View File

@ -48,6 +48,7 @@
<div class="up-card">
<form method="post" class="up-form">
@Html.AntiForgeryToken()
<div class="up-field">
<label asp-for="NewVerses.VOrder">مصرع‌ها قبل از کدام مصرع می‌بایست درج شوند</label>
<select asp-for="NewVerses.VOrder">

View File

@ -16,7 +16,6 @@ using System.Linq;
namespace GanjooRazor.Areas.User.Pages
{
[IgnoreAntiforgeryToken(Order = 1001)]
public class VerseAddPageModel : PageModel
{
/// <summary>

View File

@ -24,6 +24,7 @@
@if (Model.LoggedIn)
{
<form method="post" action="?handler=Logout">
@Html.AntiForgeryToken()
<table>
<tr>
<td>
@ -45,6 +46,7 @@
else
{
<form method="post" action="@("?handler=Login&redirect=" + Model.RedirectUrlEncoded)">
@Html.AntiForgeryToken()
<table>
<tr>
<td>

View File

@ -5,7 +5,6 @@ using System.Net.Http;
namespace GanjooRazor.Pages
{
[IgnoreAntiforgeryToken(Order = 1001)]
public class LoginModel : LoginPartialEnabledPageModel
{

View File

@ -29,6 +29,7 @@
if (Model.PhaseSendEmail)
{
<form method="post" action="/resetpassword?Handler=SendEmail">
@Html.AntiForgeryToken()
<table class="font-size-1em">
@ -97,6 +98,7 @@
if (Model.PhaseVerify)
{
<form method="post" action="/resetpassword?Handler=Verify">
@Html.AntiForgeryToken()
<table class="font-size-1em">
@ -134,6 +136,7 @@
else
{
<form method="post" action="/resetpassword?Handler=Phase3">
@Html.AntiForgeryToken()
<table class="font-size-1em">

View File

@ -17,7 +17,6 @@ using System.Threading.Tasks;
namespace GanjooRazor.Pages
{
[IgnoreAntiforgeryToken(Order = 1001)]
public class ResetPasswordModel : PageModel
{
/// <summary>

View File

@ -30,6 +30,7 @@
if (Model.SignupPhase1)
{
<form method="post" action="/signup?Handler=Phase1">
@Html.AntiForgeryToken()
<table class="font-size-1em">
<tr class="nobackground">
@ -110,6 +111,7 @@
if (Model.SignupVerifyEmailPhase)
{
<form method="post" action="/signup?Handler=Phase2">
@Html.AntiForgeryToken()
<table class="font-size-1em">
<tr class="nobackground">
@ -144,6 +146,7 @@
else
{
<form method="post" action="/signup?Handler=Phase3">
@Html.AntiForgeryToken()
<table class="font-size-1em">
<tr class="nobackground">

View File

@ -16,7 +16,6 @@ using System.Threading.Tasks;
namespace GanjooRazor.Pages
{
[IgnoreAntiforgeryToken(Order = 1001)]
public class SignUpModel : PageModel
{
/// <summary>

View File

@ -83,6 +83,7 @@
<div class="content">
<form method="post">
@Html.AntiForgeryToken()
<span class="inputlabel">چرا باید این حاشیه حذف شود؟</span><br>
<input type="radio" asp-for="Report.ReasonCode" value="offensive">توهین‌آمیز است.<br>
<input type="radio" asp-for="Report.ReasonCode" value="religious ">بحث مذهبی کرده.<br>

View File

@ -9,7 +9,6 @@ using System.Threading.Tasks;
namespace GanjooRazor.Pages
{
[IgnoreAntiforgeryToken(Order = 1001)]
public class ReportCommentModel : PageModel
{
/// <summary>

Some files were not shown because too many files have changed in this diff Show More