Skip to content
Closed
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
69 changes: 69 additions & 0 deletions Zero-K.info/AppCode/PostLinkExtensions.cs
Original file line number Diff line number Diff line change
@@ -0,0 +1,69 @@
using System.Web.Mvc.Html;
using System.Web.Routing;

namespace System.Web.Mvc
{
/// <summary>
/// Renders a link-looking control that submits via POST and carries an anti-forgery token.
/// Used for actions that change state: a plain &lt;a&gt; leaves them reachable by GET, which means
/// any third-party page can trigger them with the visitor's cookies attached.
/// Pass cssClass "js_confirm" to reuse the site's existing confirmation dialog.
/// </summary>
public static class PostLinkExtensions
{
/// <summary>Text link that POSTs to an action.</summary>
public static MvcHtmlString PostLink(this HtmlHelper html,
string linkText,
string action,
string controller = null,
object routeValues = null,
string cssClass = null,
string nicetitle = null) {
return BuildPostForm(html, HttpUtility.HtmlEncode(linkText ?? ""), action, controller, routeValues, cssClass, nicetitle);
}

/// <summary>Image link that POSTs to an action. imageHeight of 0 omits the attribute.</summary>
public static MvcHtmlString PostImageLink(this HtmlHelper html,
string imageSrc,
int imageHeight,
string action,
string controller = null,
object routeValues = null,
string cssClass = null,
string nicetitle = null) {
var img = new TagBuilder("img");
img.Attributes["src"] = imageSrc;
if (imageHeight > 0) img.Attributes["height"] = imageHeight.ToString();
img.Attributes["alt"] = "";
return BuildPostForm(html, img.ToString(TagRenderMode.SelfClosing), action, controller, routeValues, cssClass, nicetitle);
}

static MvcHtmlString BuildPostForm(HtmlHelper html,
string innerHtml,
string action,
string controller,
object routeValues,
string cssClass,
string nicetitle) {
var urlHelper = new UrlHelper(html.ViewContext.RequestContext);
var values = routeValues == null ? new RouteValueDictionary() : new RouteValueDictionary(routeValues);
var url = controller == null ? urlHelper.Action(action, values) : urlHelper.Action(action, controller, values);

var form = new TagBuilder("form");
form.Attributes["method"] = "post";
form.Attributes["action"] = url;
form.AddCssClass("postlink");

var button = new TagBuilder("button");
button.Attributes["type"] = "submit";
// site_main.js skips .postlink-button when it buttonifies :submit with jQuery UI
button.AddCssClass("postlink-button");
if (!string.IsNullOrEmpty(cssClass)) button.AddCssClass(cssClass);
if (!string.IsNullOrEmpty(nicetitle)) button.Attributes["nicetitle"] = nicetitle;
button.InnerHtml = innerHtml;

form.InnerHtml = html.AntiForgeryToken().ToHtmlString() + button.ToString(TagRenderMode.Normal);
return new MvcHtmlString(form.ToString(TagRenderMode.Normal));
}
}
}
1 change: 1 addition & 0 deletions Zero-K.info/Controllers/ContributionsController.cs
Original file line number Diff line number Diff line change
Expand Up @@ -44,6 +44,7 @@ public ActionResult ThankYou() {
/// <summary>
/// Manually input a contribution
/// </summary>
[HttpPost]
[ValidateAntiForgeryToken]
[Auth(Role = AdminLevel.Moderator)]
public ActionResult AddContribution(int accountID,int kudos, string item, string currency, double gross, double grossEur, double netEur, string email, string comment, bool isSpring, DateTime date) {
Expand Down
12 changes: 12 additions & 0 deletions Zero-K.info/Controllers/FactionsController.cs
Original file line number Diff line number Diff line change
Expand Up @@ -116,6 +116,9 @@ public ActionResult NewTreaty(int? acceptingFactionID) {
/// <param name="delete">Delete the specified <see cref="TreatyEffect"/>?</param>
/// <param name="propose">If not null or empty, this is a newly proposed treaty</param>
/// <returns></returns>
[Auth]
[HttpPost]
[ValidateAntiForgeryToken]
public ActionResult ModifyTreaty(int factionTreatyID,
int? turns,
int? acceptingFactionID,
Expand Down Expand Up @@ -203,6 +206,9 @@ public ActionResult ModifyTreaty(int factionTreatyID,



[Auth]
[HttpPost]
[ValidateAntiForgeryToken]
public ActionResult CancelTreaty(int id) {
var db = new ZkDataContext();
var treaty = db.FactionTreaties.Single(x => x.FactionTreatyID == id);
Expand All @@ -218,6 +224,9 @@ public ActionResult CancelTreaty(int id) {
return Content("Cannot cancel");
}

[Auth]
[HttpPost]
[ValidateAntiForgeryToken]
public ActionResult CounterProposal(int id) {
var db = new ZkDataContext();
var treaty = db.FactionTreaties.Single(x => x.FactionTreatyID == id);
Expand Down Expand Up @@ -292,6 +301,9 @@ public ActionResult AcceptTreaty(int id) {
/// <summary>
/// Set faction secret topic (applied to lobby channel as well)
/// </summary>
[Auth]
[HttpPost]
[ValidateAntiForgeryToken]
public ActionResult SetTopic(int factionID, string secretTopic) {
var db = new ZkDataContext();
var fac = db.Factions.Single(x => x.FactionID == factionID);
Expand Down
1 change: 1 addition & 0 deletions Zero-K.info/Controllers/ForumController.cs
Original file line number Diff line number Diff line change
Expand Up @@ -538,6 +538,7 @@ public ActionResult Thread(int? id, int? postID) {
return View(res);
}

[HttpPost]
[ValidateAntiForgeryToken]
[Auth(Role = AdminLevel.Moderator)]
public ActionResult AdminThread(int threadID, int newcat, bool isPinned, bool isLocked) {
Expand Down
4 changes: 4 additions & 0 deletions Zero-K.info/Controllers/LobbyController.cs
Original file line number Diff line number Diff line change
Expand Up @@ -94,6 +94,8 @@ public async Task<ActionResult> AddBlockedHost(string hostname, string comment)
}

//[ValidateAntiForgeryToken]
[HttpPost]
[ValidateAntiForgeryToken]
[Auth(Role = AdminLevel.Moderator)]
public async Task<ActionResult> RemoveBlockedCompany(int companyID)
{
Expand All @@ -108,6 +110,8 @@ public async Task<ActionResult> RemoveBlockedCompany(int companyID)
}

//[ValidateAntiForgeryToken]
[HttpPost]
[ValidateAntiForgeryToken]
[Auth(Role = AdminLevel.Moderator)]
public async Task<ActionResult> RemoveBlockedHost(int hostID)
{
Expand Down
3 changes: 3 additions & 0 deletions Zero-K.info/Controllers/LobbyNewsController.cs
Original file line number Diff line number Diff line change
Expand Up @@ -28,6 +28,8 @@ public ActionResult Edit(int? id)
return View("LobbyNewsEdit", db.LobbyNews.Find(id));
}

[HttpPost]
[ValidateAntiForgeryToken]
[Auth(Role = AdminLevel.Moderator)]
public ActionResult Delete(int id)
{
Expand All @@ -45,6 +47,7 @@ public ActionResult Delete(int id)
/// </summary>
/// <param name="nn">The existing <see cref="News"/> item, if editing</param>
/// <remarks>Also makes or edits a <see cref="ForumThread"/> and its starting <see cref="ForumPost"/></remarks>
[HttpPost]
[ValidateAntiForgeryToken]
[Auth(Role = AdminLevel.Moderator)]
[ValidateInput(false)]
Expand Down
3 changes: 3 additions & 0 deletions Zero-K.info/Controllers/MapBansController.cs
Original file line number Diff line number Diff line change
Expand Up @@ -46,6 +46,9 @@ public ActionResult Index()
/// </summary>
///

[Auth]
[HttpPost]
[ValidateAntiForgeryToken]
public ActionResult Update(List<Resource> resources)
{
if (resources == null) return Content("No input given");
Expand Down
7 changes: 7 additions & 0 deletions Zero-K.info/Controllers/MapsController.cs
Original file line number Diff line number Diff line change
Expand Up @@ -207,6 +207,7 @@ public JsonResult JsonSearch(string search,
/// Brings up the planet image selector page
/// </summary>
/// <param name="resourceID">The ID of the map to assign a planet image to</param>
[Auth(Role = AdminLevel.Moderator)]
public ActionResult PlanetImageSelect(int resourceID) {
var res = new PlanetImageSelectData();
var db = new ZkDataContext();
Expand Down Expand Up @@ -239,6 +240,9 @@ public ActionResult Rate(int id, int rating) {
return Content("");
}

[Auth(Role = AdminLevel.Moderator)]
[HttpPost]
[ValidateAntiForgeryToken]
public ActionResult RemovePlanetIcon(int resourceID) {
var db = new ZkDataContext();
var res = db.Resources.Single(x => x.ResourceID == resourceID);
Expand All @@ -247,6 +251,9 @@ public ActionResult RemovePlanetIcon(int resourceID) {
return RedirectToAction("Detail", new { id = res.ResourceID });
}

[Auth(Role = AdminLevel.Moderator)]
[HttpPost]
[ValidateAntiForgeryToken]
public ActionResult SubmitPlanetIcon(int resourceID, string icon) {
var db = new ZkDataContext();
var res = db.Resources.Single(x => x.ResourceID == resourceID);
Expand Down
5 changes: 5 additions & 0 deletions Zero-K.info/Controllers/MissionsController.cs
Original file line number Diff line number Diff line change
Expand Up @@ -13,6 +13,7 @@ public class MissionsController : Controller
// GET: /Missions/


[HttpPost]
[ValidateAntiForgeryToken]
[Auth(Role = AdminLevel.Moderator)]
public ActionResult ChangeFeaturedOrder(int id, float? featuredOrder, string script)
Expand All @@ -31,6 +32,8 @@ public ActionResult ChangeFeaturedOrder(int id, float? featuredOrder, string scr
}

//[ValidateAntiForgeryToken]
[HttpPost]
[ValidateAntiForgeryToken]
[Auth(Role = AdminLevel.Moderator)]
public ActionResult Delete(int id)
{
Expand Down Expand Up @@ -153,6 +156,8 @@ public ActionResult Script(int id)
}

//[ValidateAntiForgeryToken]
[HttpPost]
[ValidateAntiForgeryToken]
[Auth(Role = AdminLevel.Moderator)]
public ActionResult Undelete(int id)
{
Expand Down
3 changes: 3 additions & 0 deletions Zero-K.info/Controllers/MyController.cs
Original file line number Diff line number Diff line change
Expand Up @@ -252,6 +252,9 @@ public ActionResult Index()
/// <summary>
/// Reset all the user's unlocks
/// </summary>
[Auth]
[HttpPost]
[ValidateAntiForgeryToken]
public ActionResult Reset()
{
var db = new ZkDataContext();
Expand Down
1 change: 1 addition & 0 deletions Zero-K.info/Controllers/NewsController.cs
Original file line number Diff line number Diff line change
Expand Up @@ -34,6 +34,7 @@ public ActionResult Detail(int id) {
/// </summary>
/// <param name="nn">The existing <see cref="News"/> item, if editing</param>
/// <remarks>Also makes or edits a <see cref="ForumThread"/> and its starting <see cref="ForumPost"/></remarks>
[HttpPost]
[ValidateAntiForgeryToken]
[Auth(Role = AdminLevel.Moderator)]
[ValidateInput(false)]
Expand Down
14 changes: 14 additions & 0 deletions Zero-K.info/Controllers/PlanetwarsAdminController.cs
Original file line number Diff line number Diff line change
Expand Up @@ -149,6 +149,8 @@ private static void PurgeGalaxy(int galaxyID, bool unassignFactions, bool resetR

}

[HttpPost]
[ValidateAntiForgeryToken]
public ActionResult SetDefault(int galaxyid)
{
var db = new ZkDataContext();
Expand All @@ -158,6 +160,8 @@ public ActionResult SetDefault(int galaxyid)
return RedirectToAction("Index");
}

[HttpPost]
[ValidateAntiForgeryToken]
[Auth(Role = AdminLevel.SuperAdmin)]
public ActionResult Delete(int galaxyid)
{
Expand All @@ -168,6 +172,8 @@ public ActionResult Delete(int galaxyid)
return RedirectToAction("Index");
}

[HttpPost]
[ValidateAntiForgeryToken]
public ActionResult SetPlanetTeamSizes(int galaxyID)
{
var db = new ZkDataContext();
Expand All @@ -189,6 +195,8 @@ public ActionResult SetPlanetTeamSizes(int galaxyID)
return RedirectToAction("Index");
}

[HttpPost]
[ValidateAntiForgeryToken]
public ActionResult RandomizeMaps(int galaxyID)
{
using (var db = new ZkDataContext())
Expand Down Expand Up @@ -232,6 +240,8 @@ public ActionResult ResetRatings()
return RedirectToAction("Index");
}

[HttpPost]
[ValidateAntiForgeryToken]
public ActionResult AddWormholes(int galaxyID)
{
var db = new ZkDataContext();
Expand All @@ -246,6 +256,8 @@ public ActionResult AddWormholes(int galaxyID)
return RedirectToAction("Index");
}

[HttpPost]
[ValidateAntiForgeryToken]
public ActionResult OwnPlanets(int galaxyID)
{
var db = new ZkDataContext();
Expand Down Expand Up @@ -290,6 +302,8 @@ public ActionResult OwnPlanets(int galaxyID)
return RedirectToAction("Index");
}

[HttpPost]
[ValidateAntiForgeryToken]
public ActionResult StartGalaxy(int galaxyID)
{
AddWormholes(galaxyID);
Expand Down
8 changes: 8 additions & 0 deletions Zero-K.info/Controllers/PlanetwarsController.cs
Original file line number Diff line number Diff line change
Expand Up @@ -439,6 +439,8 @@ public ActionResult RunSetPlanetOwners()



[HttpPost]
[ValidateAntiForgeryToken]
[Auth(Role = AdminLevel.Moderator)]
public ActionResult SubmitRenamePlanet(int planetID, string newName, int teamSize, string map)
{
Expand All @@ -461,6 +463,9 @@ public ActionResult SubmitRenamePlanet(int planetID, string newName, int teamSiz
}


[Auth]
[HttpPost]
[ValidateAntiForgeryToken]
public ActionResult RecallRole(int accountID, int roletypeID)
{
var db = new ZkDataContext();
Expand All @@ -482,6 +487,9 @@ public ActionResult RecallRole(int accountID, int roletypeID)
else return Content("Cannot recall");
}

[Auth]
[HttpPost]
[ValidateAntiForgeryToken]
public ActionResult AppointRole(int accountID, int roletypeID)
{
var db = new ZkDataContext();
Expand Down
5 changes: 5 additions & 0 deletions Zero-K.info/Controllers/PollController.cs
Original file line number Diff line number Diff line change
Expand Up @@ -21,6 +21,7 @@ public ActionResult Index(int pollID)
return null;
}

[HttpPost]
[ValidateAntiForgeryToken]
[Auth(Role = AdminLevel.Moderator)]
public ActionResult NewPoll(string question, string answers, bool? isAnonymous)
Expand Down Expand Up @@ -195,6 +196,8 @@ public ActionResult PollVote(int pollID)
}

//[ValidateAntiForgeryToken]
[HttpPost]
[ValidateAntiForgeryToken]
[Auth(Role = AdminLevel.Moderator)]
public ActionResult SwapHeadline(int pollid)
{
Expand All @@ -217,6 +220,8 @@ public ActionResult UserVotes(int? id)
return View("PollUserVotes", acc);
}

[HttpPost]
[ValidateAntiForgeryToken]
[Auth(Role = AdminLevel.Moderator)]
public ActionResult SwapVisible(int pollid)
{
Expand Down
4 changes: 2 additions & 2 deletions Zero-K.info/Scripts/site_main.js
Original file line number Diff line number Diff line change
Expand Up @@ -205,8 +205,8 @@ function GlobalPageInit(root) {
s.find(".js_datetimepicker").datetimepicker();

// buttonification
s.find(":submit").button();
s.find(":button").button();
s.find(":submit").not(".postlink-button").button();
s.find(":button").not(".postlink-button").button();
s.find(".js_button").button();
s.find(".js_accordion").accordion();

Expand Down
Loading