diff options
author | Sebastian Reichel <sre@ring0.de> | 2018-07-18 23:54:49 +0200 |
---|---|---|
committer | Sebastian Reichel <sre@ring0.de> | 2018-07-20 23:41:34 +0200 |
commit | adc439496804ab9eb405e18d8a5e74d340e055eb (patch) | |
tree | 1c93c7a4c1819e4c3a295a1bae41aeca9659a545 | |
parent | 5f0fd3619b10668f1bc005315126b944140ea1e7 (diff) | |
download | serial-barcode-scanner-adc439496804ab9eb405e18d8a5e74d340e055eb.tar.bz2 |
web: don't allow non-logged in person to view guest account
-rw-r--r-- | src/web/web.vala | 2 |
1 files changed, 1 insertions, 1 deletions
diff --git a/src/web/web.vala b/src/web/web.vala index 8934763..dbfcb54 100644 --- a/src/web/web.vala +++ b/src/web/web.vala @@ -336,7 +336,7 @@ public class WebServer { try { var session = new WebSession(server, msg, path, query, client); - if(id != session.user && !(session.superuser || session.auth_users)) { + if(id == 0 || id != session.user && !(session.superuser || session.auth_users)) { handler_403(server, msg, path, query, client); return; } |