Compare commits

...

5 Commits

Author SHA1 Message Date
Raphael Michel
516e0df0ff Bump to 2.8.2 2019-06-05 16:45:36 +02:00
Raphael Michel
f6f3f74d8f Fix invalid signature 2019-06-05 16:45:11 +02:00
Raphael Michel
435fe2992b Release again 2019-06-05 16:38:49 +02:00
Raphael Michel
750cd4839c Bump to 2.8.1 2019-06-05 16:28:12 +02:00
Raphael Michel
4fb6f6ab7d [SECURITY] Do not allow to enumerate organizers 2019-06-05 16:28:03 +02:00
2 changed files with 11 additions and 5 deletions

View File

@@ -1 +1 @@
__version__ = "2.8.0"
__version__ = "2.8.2"

View File

@@ -149,10 +149,16 @@ def nav_context_list(request):
]
if show_user and organizer:
organizer = serialize_orga(Organizer.objects.get(pk=organizer))
if organizer in results:
results.remove(organizer)
results.insert(1, organizer)
try:
organizer = Organizer.objects.get(pk=organizer)
except Organizer.DoesNotExist:
pass
else:
if request.user.has_organizer_permission(organizer, request=request):
organizer = serialize_orga(organizer)
if organizer in results:
results.remove(organizer)
results.insert(1, organizer)
doc = {
'results': results,