diff --git a/files/routes/settings.py b/files/routes/settings.py index 692082909f..0824ba3c3f 100644 --- a/files/routes/settings.py +++ b/files/routes/settings.py @@ -825,8 +825,9 @@ def settings_css_get(v): @auth_required @validate_formkey def settings_css(v): - css = request.values.get("css").strip().replace('\\', '').strip()[:4000] + if v.agendaposter: return {"error": "Agendapostered users can edit css!"} + css = request.values.get("css").strip().replace('\\', '').strip()[:4000] v.css = css g.db.add(v) g.db.commit()