harden everything more
This commit is contained in:
parent
bba2500473
commit
389c1c1cdc
2 changed files with 70 additions and 2 deletions
5
index.js
5
index.js
|
|
@ -100,7 +100,10 @@ app.use("/plumbing", require("./plumbing"));
|
|||
// the whole editor: a private structure 404s for anyone who isn't on its member
|
||||
// list, exactly like its user-facing routes do.
|
||||
app.param("structure_id", (req, res, next, id) => {
|
||||
if (!model.canAccessStructure(req.session.userId, id)) {
|
||||
// The prime structure (id 0) is kernel infrastructure: its db holds users,
|
||||
// sessions and every structure's metadata. It is never editable through the
|
||||
// workshop by anyone, logged in or not — treat it as if it doesn't exist.
|
||||
if (Number(id) === 0 || !model.canAccessStructure(req.session.userId, id)) {
|
||||
// Logged-out visitors get a chance to sign in and come back; logged-in
|
||||
// non-members stay 404 so we never confirm the structure exists to them.
|
||||
if (!req.session.userId && req.method === "GET") {
|
||||
|
|
|
|||
Loading…
Add table
Add a link
Reference in a new issue