잉여개발기 (SPDV) 6 лет назад
Родитель
Сommit
747d4f5823
2 измененных файлов с 6 добавлено и 3 удалено
  1. 3 3
      route/view_diff_data.py
  2. 3 0
      route/view_raw.py

+ 3 - 3
route/view_diff_data.py

@@ -3,12 +3,12 @@ from .tool.func import *
 def view_diff_data_2(conn, name):
     curs = conn.cursor()
 
-    first = number_check(flask.request.args.get('first', '1'))
-    second = number_check(flask.request.args.get('second', '1'))
-    
     if acl_check(name, 'render') == 1:
         return re_error('/ban')
 
+    first = number_check(flask.request.args.get('first', '1'))
+    second = number_check(flask.request.args.get('second', '1'))
+
     curs.execute("select title from history where title = ? and (id = ? or id = ?) and hide = 'O'", [name, first, second])
     if curs.fetchall() and admin_check(6) != 1:
         return re_error('/error/3')

+ 3 - 0
route/view_raw.py

@@ -3,6 +3,9 @@ from .tool.func import *
 def view_raw_2(conn, name, sub_title, num):
     curs = conn.cursor()
 
+    if acl_check(name, 'render') == 1:
+        return re_error('/ban')
+    
     v_name = name
     sub = ' (' + load_lang('raw') + ')'