diff --git a/files/routes/awards.py b/files/routes/awards.py index 0632b1dbe5..8b0c41bf57 100644 --- a/files/routes/awards.py +++ b/files/routes/awards.py @@ -327,7 +327,10 @@ def admin_userawards_post(v): if v.admin_level < 6: abort(403) - u = get_user(request.values.get("username", '1'), graceful=False, v=v) + try: u = request.values.get("username").strip() + except: abort(404) + + u = get_user(u, graceful=False, v=v) notify_awards = {}