mirror of
https://github.com/pretix/pretix.git
synced 2026-05-06 15:24:02 +00:00
[SECURITY] Do not allow to enumerate organizers
This commit is contained in:
@@ -149,10 +149,15 @@ def nav_context_list(request):
|
||||
]
|
||||
|
||||
if show_user and organizer:
|
||||
organizer = serialize_orga(Organizer.objects.get(pk=organizer))
|
||||
if organizer in results:
|
||||
results.remove(organizer)
|
||||
results.insert(1, organizer)
|
||||
try:
|
||||
organizer = serialize_orga(Organizer.objects.get(pk=organizer))
|
||||
except Organizer.DoesNotExist:
|
||||
pass
|
||||
else:
|
||||
if request.user.has_organizer_permission(organizer, request):
|
||||
if organizer in results:
|
||||
results.remove(organizer)
|
||||
results.insert(1, organizer)
|
||||
|
||||
doc = {
|
||||
'results': results,
|
||||
|
||||
Reference in New Issue
Block a user