1
0
Fork 0
mirror of https://gitlab.com/SIGBUS/nyaa.git synced 2024-12-22 19:10:00 +00:00

make admin unable to set own user class, fix missing post method

This commit is contained in:
martstern 2017-05-17 09:17:08 -04:00
parent 931b2b0b83
commit 04047a5712

View file

@ -206,14 +206,14 @@ def home(rss):
rss_filter=rss_query_string) rss_filter=rss_query_string)
@app.route('/user/<user_name>') @app.route('/user/<user_name>', methods=['GET', 'POST'])
def view_user(user_name): def view_user(user_name):
user = models.User.by_username(user_name) user = models.User.by_username(user_name)
if not user: if not user:
flask.abort(404) flask.abort(404)
if flask.g.user: if flask.g.user and flask.g.user.id != user.id:
admin = flask.g.user.is_admin admin = flask.g.user.is_admin
superadmin = flask.g.user.is_superadmin superadmin = flask.g.user.is_superadmin
else: else: