Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

在添加一个新评论时没有进行photo.can_comment验证 #24

Open
amchii opened this issue Jun 16, 2019 · 1 comment
Open

在添加一个新评论时没有进行photo.can_comment验证 #24

amchii opened this issue Jun 16, 2019 · 1 comment
Labels
bug Something isn't working

Comments

@amchii
Copy link

amchii commented Jun 16, 2019

def new_comment(photo_id):

虽然说当photo.can_comment为False时不会渲染评论表单,但是完全可以获得一个csrf_token然后按照格式post,在网站demo中测试成功。
http://albumy.helloflask.com/photo/636?page=1 其中内容为2的评论就是我在comment disabled下提交的。

@greyli greyli added the bug Something isn't working label Jul 7, 2019
@greyli
Copy link
Owner

greyli commented Jul 7, 2019

Good catch!

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
bug Something isn't working
Projects
None yet
Development

No branches or pull requests

2 participants