make admin unable to set own user class, fix missing post method

This commit is contained in:
martstern 2017-05-17 09:17:08 -04:00
parent 931b2b0b83
commit 04047a5712
1 changed files with 2 additions and 2 deletions

View File

@ -206,14 +206,14 @@ def home(rss):
rss_filter=rss_query_string)
@app.route('/user/<user_name>')
@app.route('/user/<user_name>', methods=['GET', 'POST'])
def view_user(user_name):
user = models.User.by_username(user_name)
if not user:
flask.abort(404)
if flask.g.user:
if flask.g.user and flask.g.user.id != user.id:
admin = flask.g.user.is_admin
superadmin = flask.g.user.is_superadmin
else: