summaryrefslogtreecommitdiffstats
diff options
context:
space:
mode:
authorSebastian Reichel <sre@ring0.de>2018-07-18 23:54:49 +0200
committerSebastian Reichel <sre@ring0.de>2018-07-20 23:41:34 +0200
commitadc439496804ab9eb405e18d8a5e74d340e055eb (patch)
tree1c93c7a4c1819e4c3a295a1bae41aeca9659a545
parent5f0fd3619b10668f1bc005315126b944140ea1e7 (diff)
downloadserial-barcode-scanner-adc439496804ab9eb405e18d8a5e74d340e055eb.tar.bz2
web: don't allow non-logged in person to view guest account
-rw-r--r--src/web/web.vala2
1 files changed, 1 insertions, 1 deletions
diff --git a/src/web/web.vala b/src/web/web.vala
index 8934763..dbfcb54 100644
--- a/src/web/web.vala
+++ b/src/web/web.vala
@@ -336,7 +336,7 @@ public class WebServer {
try {
var session = new WebSession(server, msg, path, query, client);
- if(id != session.user && !(session.superuser || session.auth_users)) {
+ if(id == 0 || id != session.user && !(session.superuser || session.auth_users)) {
handler_403(server, msg, path, query, client);
return;
}