Skip to content

Commit 2756293

Browse files
committed
security check for user creation
1 parent ec644f1 commit 2756293

1 file changed

Lines changed: 7 additions & 2 deletions

File tree

userManagment/views.py

Lines changed: 7 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -91,7 +91,6 @@ def apiAccess(request):
9191
logging.CyberCPLogFileWriter.writeToFile(str(msg))
9292
return redirect(loadLoginPage)
9393

94-
9594
def saveChangesAPIAccess(request):
9695
try:
9796
userID = request.session['userID']
@@ -123,7 +122,6 @@ def saveChangesAPIAccess(request):
123122
json_data = json.dumps(finalResponse)
124123
return HttpResponse(json_data)
125124

126-
127125
def submitUserCreation(request):
128126
try:
129127

@@ -200,6 +198,13 @@ def submitUserCreation(request):
200198
newAdmin.save()
201199
elif currentACL['createNewUser'] == 1:
202200

201+
if selectedACL != 'user':
202+
data_ret = {'status': 0, 'createStatus': 0,
203+
'error_message': "You are not authorized to access this resource."}
204+
205+
final_json = json.dumps(data_ret)
206+
return HttpResponse(final_json)
207+
203208
newAdmin = Administrator(firstName=firstName,
204209
lastName=lastName,
205210
email=email,

0 commit comments

Comments
 (0)