diff --git a/files/routes/awards.py b/files/routes/awards.py index 32321100bb..39489d99ad 100644 --- a/files/routes/awards.py +++ b/files/routes/awards.py @@ -633,7 +633,7 @@ def award_comment(cid, v): @app.get("/admin/awards") @admin_level_required(2) def admin_userawards_get(v): - if request.host == 'pcmemes.net': abort(403) + if request.host == 'pcmemes.net' and v.admin_level < 3: abort(403) if v.admin_level != 3: return render_template("admin/awards.html", awards=list(AWARDS3.values()), v=v) @@ -644,7 +644,7 @@ def admin_userawards_get(v): @limiter.limit("1/second;30/minute;200/hour;1000/day") @admin_level_required(2) def admin_userawards_post(v): - if request.host == 'pcmemes.net': abort(403) + if request.host == 'pcmemes.net' and v.admin_level < 3: abort(403) try: u = request.values.get("username").strip() except: abort(404)