threadr.lostcave.ddnss.de/templates
Joca f4bc5c925c
Remove CSRF, add password change, admin user management
Stripped all CSRF token generation, injection, and validation since it
breaks behind Apache reverse proxy. Removed handlers/csrf.go, stripped
CSRFToken from PageData, removed validateCSRFToken from all POST handlers,
and cleaned up hidden inputs and JS CSRF references.

Added self-service password change at /password/ with current-password
verification and bcrypt update. New Password link in navbar.

Extended admin panel with user management: lists all users with join dates
and allows admins to delete other users (self-deletion blocked). Added
GetAllUsers() and DeleteUser() to models.

Co-authored-by: CommandCodeBot <noreply@commandcode.ai>
2026-05-09 20:02:41 -03:00
..
pages Remove CSRF, add password change, admin user management 2026-05-09 20:02:41 -03:00
partials Remove CSRF, add password change, admin user management 2026-05-09 20:02:41 -03:00
base.html split stuff so i can read better 2026-02-20 13:37:46 -03:00