Compare commits

...

2 Commits

Author SHA1 Message Date
Raphael Michel
750cd4839c Bump to 2.8.1 2019-06-05 16:28:12 +02:00
Raphael Michel
4fb6f6ab7d [SECURITY] Do not allow to enumerate organizers 2019-06-05 16:28:03 +02:00
2 changed files with 10 additions and 5 deletions

View File

@@ -1 +1 @@
__version__ = "2.8.0" __version__ = "2.8.1"

View File

@@ -149,10 +149,15 @@ def nav_context_list(request):
] ]
if show_user and organizer: if show_user and organizer:
organizer = serialize_orga(Organizer.objects.get(pk=organizer)) try:
if organizer in results: organizer = serialize_orga(Organizer.objects.get(pk=organizer))
results.remove(organizer) except Organizer.DoesNotExist:
results.insert(1, organizer) pass
else:
if request.user.has_organizer_permission(organizer, request):
if organizer in results:
results.remove(organizer)
results.insert(1, organizer)
doc = { doc = {
'results': results, 'results': results,