Version 0.4.3 of Braindump, I Need More Functional Tests.
Yesterday, I shipped a new release of braindump. It was awesome. Until I tried to use it this morning and realized that notes were no longer being saved when you edit them. So today I cut a new release that fixes that bug, as well as implementing a new feature where you can see what notes you have shared in the past. This also addresses an issue with sharing notes, so you should be able to send notes via email again. Normally, when a product is being released on a regular cadence it is exciting. In this case, it just means that I really need more functional tests.
Post Mortem of Note Saving Bug
For those who are curious, I will document what happened in the hopes that it does not affect others in the future. Braindump was originally written using WTForms, which has CSRF protection built in so you don't have to think about it. Recently, I have begun transitioning away from WTForms in lieu of regular forms that are submitted via AJAX. The most visible benefit is that you can see and edit all of your notes from the main page, instead of having to click into each note in order to edit it. After switching to AJAX, I quickly realized that I was no longer sending a CSRF token with POST and PUT requests, which is probably a bad thing. I enabled it in the previous release. Even though I got this to work in the login and registration modal (which are true forms), I didn't consider the PUT request when editing a note. This is not a form at all, but a method that fires whenever you stop typing. Naturally, since there was no token and the endpoint was not marked as exempt, the response was a 400 error (missing CSRF token). My solution was to add the token as a meta tag to every page, and then send it along in the request headers of the AJAX call.Enable CSRF
// app/__init__.pycsrf = CsrfProtect()
def create_app(config_name): … csrf.init_app(app) …
return app
Token in the Header
// app/templates/app/app_base.html // This works because csrf_token() is in the global scope.<meta name=“csrf-token” content=" csrf_token() " />
AJAX Method to add the token before sending the PUT request.
// frontend/js/src/braindump.editor.jssaveNote: function(id, content) {
var csrftoken = $('meta[name=csrf-token]').attr('content') $.ajax({ beforeSend: function(xhr) { xhr.setRequestHeader("X-CSRFToken", csrftoken) }, url: `/edit/<span class="cp">${</span><span class="nb">id</span><span class="cp">}</span>`, data: JSON.stringify({ 'body': content, }), contentType: 'application/json', type: 'PUT', success: function (response) { console.log(response); }, error: function (error) { console.error(error); } });},
Thank you for reading! Share your thoughts with me on bluesky, mastodon, or via email.
Check out some more stuff to read down below.
Most popular posts this month
- Lev Lazinskiy
- Lev Lazinskiy
- Terminal RSS Reader With Nom
- Setting up ANTLR4 on Windows
- SQLite DB Migrations with PRAGMA user_version
Recent Favorite Blog Posts
This is a collection of the last 8 posts that I bookmarked.
- No-One Escapes the Permanent Underclass from Fernando Borretti
- Is it ethical to use AI? from charity.wtf
- The logical destination of LLMs from Andy Bell
- Revised rules of engineering leadership. from Irrational Exuberance
- The circus freaks of open source from Drew DeVault's blog
- Clanker: A Word For The Machine from Armin Ronacher's Thoughts and Writings
- I ran a half-marathon! from gluecko.se
- My Running Tips from Kevin Bell's Blog
Articles from blogs I follow around the net
My last 5 books - July 2026 edition
My last 5 books - July 2026 edition This is a new feature in which I will copy and paste my recent book reviews from my books page These are the last 5 books I have read. I will update in a month or 2 when I've read 5 more. I'm Starting to Worry About this...
via O'DonnellWeb July 12, 2026“Animating something and animating something well are two very different things.”
From Jakub Krehel, a new blog post about self constraint in the era when AI makes it easy to ignore constraints altogether. My caveat is that the post doesn’t fully come together for me – jumping from AI to animations and then back to AI the way the author...
via Unsung July 12, 2026Generated and suppressed demand.
Eight years ago, I wrote about my theory of restoring struggling teams, which came down to four steps: A team is falling behind if each week their backlog is longer than the week before. Solve by hiring more. A team is treading water if they’re able to get...
via Irrational Exuberance July 11, 2026Generated by openring