css: redirect

master
justcool393 2022-11-07 20:53:57 -06:00
parent ddbe3de33b
commit 7a0fe8015e
1 changed files with 1 additions and 4 deletions

View File

@ -540,9 +540,7 @@ def settings_css_get(v):
@auth_required @auth_required
def settings_css(v): def settings_css(v):
if v.agendaposter: abort(400, "Agendapostered users can't edit CSS!") if v.agendaposter: abort(400, "Agendapostered users can't edit CSS!")
css = request.values.get("css").strip().replace('\\', '').strip()[:4000] css = request.values.get("css").strip().replace('\\', '').strip()[:4000]
if '</style' in css.lower(): if '</style' in css.lower():
abort(400, "Please message @Aevann if you get this error") abort(400, "Please message @Aevann if you get this error")
@ -557,14 +555,13 @@ def settings_css(v):
@auth_required @auth_required
def settings_profilecss(v): def settings_profilecss(v):
profilecss = request.values.get("profilecss").strip().replace('\\', '').strip()[:4000] profilecss = request.values.get("profilecss").strip().replace('\\', '').strip()[:4000]
valid, error = validate_css(profilecss) valid, error = validate_css(profilecss)
if not valid: if not valid:
return render_template("settings_css.html", error=error, v=v) return render_template("settings_css.html", error=error, v=v)
v.profilecss = profilecss v.profilecss = profilecss
g.db.add(v) g.db.add(v)
return render_template("settings_css.html", v=v) return redirect('/settings/css')
@app.get("/settings/security") @app.get("/settings/security")
@auth_required @auth_required