[SECURITY] Do not allow to enumerate organizers

This commit is contained in:
Raphael Michel
2019-06-05 16:27:21 +02:00
parent b66a35df7a
commit e0c432d014

View File

@@ -149,7 +149,12 @@ def nav_context_list(request):
] ]
if show_user and organizer: if show_user and organizer:
try:
organizer = serialize_orga(Organizer.objects.get(pk=organizer)) organizer = serialize_orga(Organizer.objects.get(pk=organizer))
except Organizer.DoesNotExist:
pass
else:
if request.user.has_organizer_permission(organizer, request):
if organizer in results: if organizer in results:
results.remove(organizer) results.remove(organizer)
results.insert(1, organizer) results.insert(1, organizer)