mirror of
https://github.com/matt-fidd/stratos.git
synced 2026-01-01 18:19:25 +00:00
Added Class.hasAccess to validate user input and add security
This commit is contained in:
@@ -31,6 +31,9 @@ router.get('/class/:id', async (req, res) => {
|
||||
});
|
||||
}
|
||||
|
||||
if (!await c.hasAccess(await new User(null, req.session.userId)))
|
||||
return res.redirect('/admin/classes');
|
||||
|
||||
const linkRoot = `/class/${c.id}`;
|
||||
|
||||
return res.render('class', {
|
||||
|
||||
Reference in New Issue
Block a user