Commit 76bf71d2 authored by Administrator's avatar Administrator

[FIX] security fix by Samuel.

parent 286fa18a
...@@ -482,7 +482,7 @@ def graph(request, project_id, corpus_id): ...@@ -482,7 +482,7 @@ def graph(request, project_id, corpus_id):
corpus_type_id = cache.NodeType['Corpus'].id corpus_type_id = cache.NodeType['Corpus'].id
results = {} results = {}
projs = session.query(Node).filter(Node.type_id==project_type_id).all() projs = session.query(Node).filter(Node.user_id == user_id,Node.type_id==project_type_id).all()
for i in projs: for i in projs:
# print(i.id , i.name) # print(i.id , i.name)
if i.id not in results: results[i.id] = {} if i.id not in results: results[i.id] = {}
......
Markdown is supported
0% or
You are about to add 0 people to the discussion. Proceed with caution.
Finish editing this message first!
Please register or to comment