mirror of
https://github.com/aljazceru/CTFd.git
synced 2026-02-06 23:04:29 +01:00
Fixing privelege escalation due to new model default
This commit is contained in:
@@ -185,9 +185,10 @@ def can_register():
|
||||
def admins_only(f):
|
||||
@wraps(f)
|
||||
def decorated_function(*args, **kwargs):
|
||||
if session.get('admin', None) is None:
|
||||
if session.get('admin'):
|
||||
return redirect(url_for('auth.login'))
|
||||
return f(*args, **kwargs)
|
||||
else:
|
||||
return f(*args, **kwargs)
|
||||
return decorated_function
|
||||
|
||||
|
||||
|
||||
Reference in New Issue
Block a user