<form action="/admin/users/<%= user.id %>/edit" method="POST">
    <input type="hidden" name="_csrf" value="<%= csrfToken %>">
    <div class="form-group">
        <label for="username">Username</label>
        <input type="text" class="form-control" id="username" name="username" value="<%= user.username %>" required>
    </div>
    <div class="form-group">
        <label for="email">Email</label>
        <input type="email" class="form-control" id="email" name="email" value="<%= user.email %>" required>
    </div>
    <div class="form-group">
        <label for="role">Role</label>
        <select class="form-control" id="role" name="isAdmin">
            <option value="0" <%= user.isAdmin ? '' : 'selected' %>>User</option>
            <option value="1" <%= user.isAdmin ? 'selected' : '' %>>Admin</option>
        </select>
    </div>
    <button type="submit" class="btn btn-primary">Save changes</button>
</form>