Skip to content
Permalink
Browse files

Merge pull request #224 from N-Field/patch-preview-int

fix 400 errors from /api/preview
  • Loading branch information
bui committed May 9, 2020
2 parents f346e05 + 992a44b commit 224bf25fc05d3d2ea13453dc8c6d1d5c27289bf6
Showing with 2 additions and 1 deletion.
  1. +2 −1 app.py
3 app.py
@@ -341,9 +341,10 @@ def route_admin_songs_id_delete(id):
@app.cache.cached(timeout=15, query_string=True)
def route_api_preview():
song_id = request.args.get('id', None)
if not song_id or not re.match('^[0-9]+$', song_id):
if not song_id or not re.match('^[0-9]{1,9}$', song_id):
abort(400)

song_id = int(song_id)
song = db.songs.find_one({'id': song_id})
if not song:
abort(400)

0 comments on commit 224bf25

Please sign in to comment.
You can’t perform that action at this time.