Using the JWT token to auth against the form for admin

......@@ -509,13 +509,13 @@ def little_admin(db):
if admin[0] != 1:
abort(403, "You need to have an admin access")
users = db.execute('SELECT api, token, admin FROM users').fetchall()
return template('index', users=users)
return template('index', users=users, token=request.params['token'])'/admin')
def medium_admin(db):
api = request.forms.get('api')
token = request.forms.get('token')
token = request.forms.get('api_token')
admin = request.forms.get('admin')
action = request.forms.get('action')
......@@ -62,6 +62,7 @@
<div class="panel-body">
<form name="action2" class="form form-vertical" action="admin" method="post">
<input type="hidden" name="token" value="{{token}}"></input>
<div class="control-group">
<div class="controls">
......@@ -71,7 +72,7 @@
<div class="control-group">
<div class="controls">
<input name="token" type="text" class="form-control" placeholder="Token">
<input name="api_token" type="text" class="form-control" placeholder="Token">
<div class="control-group">
......@@ -98,4 +99,4 @@
<script src="static/js/jquery.min.js"></script>
<script src="static/js/bootstrap.min.js"></script>
