diff --git a/deletelink.py b/deletelink.py index f7213de798d96bdc4d9abbe8245db1c3f420f544..10f8250c62db5710c65f4f175ddd688874172e67 100644 --- a/deletelink.py +++ b/deletelink.py @@ -8,7 +8,8 @@ def deleteLink(request, s): loginbar = loginbar + "" #to hide the unused variable message except: abort(404) #if the user is not logged in, hide this page and return not found - linkToDelete = request.args.get('link') #get the link, which the user want's to delete from the parameter in the url. + linkToDelete = request.form.get('link') #get the link, which the user want's to delete from the parameter in the url. + print(linkToDelete) with connect('db/urls.db') as conn: cursor = conn.cursor() diff --git a/main.py b/main.py index 5ef70e402c235e6eb9fe34533df7b6cebf2fa2e6..ea69cc07739cc4fb224dbce9e26f77d054daa768 100644 --- a/main.py +++ b/main.py @@ -189,7 +189,7 @@ def ownLinks(pageNumber): if(loginEnabled): return userProfile(request, cookieNotice, s, pageNumber, url_scheme) else: abort(404) -@app.route('/user/delete') #This function is called if a user deletes an entrie +@app.route('/user/delete', methods=['POST']) #This function is called if a user deletes an entrie def delete(): if(loginEnabled): return deleteLink(request, s) else: abort(404) diff --git a/templates/editEntries.html b/templates/editEntries.html index ee32eaf2a0bfb626a527dd32c2593e1c618f599d..6146e82e77448726b09d150fe1e97a0442b62a2f 100644 --- a/templates/editEntries.html +++ b/templates/editEntries.html @@ -61,8 +61,9 @@ alert("error deleting link") } }; - xhttp.open("GET", link, true); - xhttp.send(); + xhttp.open("POST", "/user/delete", true); + xhttp.setRequestHeader("Content-type", "application/x-www-form-urlencoded"); + xhttp.send("link=" + link); } } </script> diff --git a/userprofile.py b/userprofile.py index c6e9a5e2fd8a7cce915741b813dcff8691b39959..e934afdaa7eb533ce22865acb0294048f0c09813 100644 --- a/userprofile.py +++ b/userprofile.py @@ -32,7 +32,7 @@ def userProfile(request, cookieNotice, s, pageNumber, url_scheme): calls = str(cursor2.execute('SELECT CALLS FROM ANALYTICS WHERE SHORT_URL=?', [entries[1]]).fetchone()[0]) except: calls = "0" - response = response + "<tr id=tr_" + str(idCounter) + ">\n<td>" + entries[0] + "</td>\n<td><a href=\"" + url_scheme + "://" + entries[1] + '">' + entries[1] + '</a></td>\n<td>' + calls + '</td>\n<td><a id="red" href="javascript:deleteLink(\'/user/delete?link=' + escape(entries[1].replace("'", "\\'")) + '\',\'tr_' + str(idCounter) + '\')">delete</a> <a href="#" id="dialog-link" onclick="buttonListener(\'' + entries[1] + '\', this)">QR</a></tr>\n' + response = response + "<tr id=tr_" + str(idCounter) + ">\n<td>" + entries[0] + "</td>\n<td><a href=\"" + url_scheme + "://" + entries[1] + '">' + entries[1] + '</a></td>\n<td>' + calls + '</td>\n<td><a id="red" href="javascript:deleteLink(\'' + escape(entries[1].replace("'", "\\'")) + '\', \'tr_' + str(idCounter) + '\')">delete</a> <a href="#" id="dialog-link" onclick="buttonListener(\'' + entries[1] + '\', this)">QR</a></tr>\n' idCounter=idCounter+1 response = response + "</table>" #Close the table