Bug 17109: Add CSRF token to [opac-]sendbasket
[srvgit] / koha-tmpl / opac-tmpl / bootstrap / en / modules / opac-sendbasketform.tt
1 [% INCLUDE 'doc-head-open.inc' %]
2 <title>[% IF ( LibraryNameTitle ) %][% LibraryNameTitle %][% ELSE %]Koha online[% END %] catalog &rsaquo;  Sending your cart</title>
3 [% INCLUDE 'doc-head-close.inc' %]
4 [% BLOCK cssinclude %][% END %]
5 </head>
6 [% INCLUDE 'bodytag.inc' bodyid='addtolist' bodyclass='popup' %]
7     <div class="main">
8         <div class="container-fluid">
9             <div class="row-fluid">
10                 <div class="span12">
11                     <div id="usersendbasket">
12                         [% IF ( email_add ) %]
13
14                             [% IF ( SENT ) %]
15                                 <h1>Message sent</h1>
16                                 <div class="dialog dialog-success">
17                                     <p>The cart was sent to: [% email_add | html %]</p>
18                                 </div>
19                                 <p><a class="focus close" href="#">Close window</a></p>
20                             [% END %]
21
22                             [% IF csrf_error %]
23                                 <p>No valid CSRF token!</p>
24                                 <p><a class="focus close" href="#">Close window</a></p>
25                             [% END %]
26                             [% IF ( error ) %]
27                                 <div class="alert">
28                                     <p>There was an error sending the cart.</p>
29                                 </div>
30                             [% END %]
31
32                         [% ELSE %]
33                             <h1>Sending your cart</h1>
34                             <form action="/cgi-bin/koha/opac-sendbasket.pl" method="post" id="sendbasketform">
35                                 <fieldset>
36                                     <label for="email_add">Email address:</label>
37                                     <input type="text" id="email_add" name="email_add" size="43" class="focus" />
38                                     <label for="comment">Comment:</label>
39                                     <textarea id="comment" name="comment" rows="4" cols="40"></textarea>
40                                     <input type="hidden" name="bib_list" value="[% bib_list %]" />
41                                     <input type="hidden" name="csrf_token" value="[% csrf_token %]" />
42                                 </fieldset>
43                                 <fieldset class="action">
44                                     <input type="submit" class="btn" value="Send" />
45                                     <a class="cancel close" href="#">Cancel</a>
46                                 </fieldset>
47                             </form>
48
49                         [% END # / IF email_add %]
50                     </div> <!-- / #usersendbasket -->
51                 </div> <!-- / .span12 -->
52             </div> <!-- / .row-fluid -->
53         </div> <!-- / .container-fluid -->
54     </div> <!-- / .main -->
55
56 [% INCLUDE 'opac-bottom.inc' is_popup=1 %]
57 [% BLOCK jsinclude %][% END %]