From b8cde6ca600919d6f53fa9005d6ec9a0c0c662da Mon Sep 17 00:00:00 2001 From: Aevann1 Date: Fri, 9 Sep 2022 11:15:16 +0200 Subject: [PATCH] restrict approving and rejecting marseys to the fish --- files/routes/static.py | 4 ++++ 1 file changed, 4 insertions(+) diff --git a/files/routes/static.py b/files/routes/static.py index 93642d32d..16977a69a 100644 --- a/files/routes/static.py +++ b/files/routes/static.py @@ -491,6 +491,8 @@ def submit_marsey(v): @app.post("/admin/approve/marsey/") @admin_level_required(3) def approve_marsey(v, name): + if v.id != CARP_ID: abort(403) + marsey = g.db.query(Marsey).filter_by(name=name).one_or_none() if not marsey: abort(404) @@ -522,6 +524,8 @@ def approve_marsey(v, name): @app.post("/admin/reject/marsey/") @admin_level_required(3) def reject_marsey(v, name): + if v.id != CARP_ID: abort(403) + marsey = g.db.query(Marsey).filter_by(name=name).one_or_none() if not marsey: abort(404)