remove id attribute from csrf token field due to obsolescence

and if there's multiple form's on the page it would lead to
multiple elements with the same id which is illegal in html
This commit is contained in:
glaszig 2019-08-01 13:11:07 +02:00
parent f36b08c10a
commit 8f3489cd4a

View file

@ -70,7 +70,7 @@ function ensureCSRFSessionToken()
function CSRFTokenFieldTag()
{
$token = htmlspecialchars($_SESSION['csrf_token']);
return '<input id="csrf_token" type="hidden" name="csrf_token" value="' . $token . '">';
return '<input type="hidden" name="csrf_token" value="' . $token . '">';
}
/**