From 07a9b79396fd260b2d9aa918751823c70ba709c2 Mon Sep 17 00:00:00 2001 From: rubenwardy Date: Tue, 20 Mar 2018 00:58:44 +0000 Subject: Check type and author in package details --- app/views/packages.py | 7 ++++++- 1 file changed, 6 insertions(+), 1 deletion(-) (limited to 'app/views') diff --git a/app/views/packages.py b/app/views/packages.py index 73c9edd..8aaf324 100644 --- a/app/views/packages.py +++ b/app/views/packages.py @@ -24,7 +24,12 @@ def txp_page(): @app.route("/s///") def package_page(type, author, name): - package = Package.query.filter_by(name=name).first() + user = User.query.filter_by(username=author).first() + if user is None: + abort(404) + + package = Package.query.filter_by(name=name, author_id=user.id, + type=PackageType.fromName(type)).first() if package is None: abort(404) -- cgit v1.2.3