From dc7145e2ddaa743fd2147a48270e539076d2c540 Mon Sep 17 00:00:00 2001 From: Kevin Chung Date: Thu, 18 Aug 2016 17:49:57 -0400 Subject: [PATCH] Fixing privelege escalation due to new model default --- CTFd/utils.py | 5 +++-- 1 file changed, 3 insertions(+), 2 deletions(-) diff --git a/CTFd/utils.py b/CTFd/utils.py index 05ef4eeb..c95f9a48 100644 --- a/CTFd/utils.py +++ b/CTFd/utils.py @@ -185,9 +185,10 @@ def can_register(): def admins_only(f): @wraps(f) def decorated_function(*args, **kwargs): - if session.get('admin', None) is None: + if session.get('admin'): return redirect(url_for('auth.login')) - return f(*args, **kwargs) + else: + return f(*args, **kwargs) return decorated_function