|
@@ -2027,7 +2027,7 @@ def change_password():
|
|
|
curs.execute("select * from user where id = '" + db_pas(request.forms.id) + "'")
|
|
curs.execute("select * from user where id = '" + db_pas(request.forms.id) + "'")
|
|
|
user = curs.fetchall()
|
|
user = curs.fetchall()
|
|
|
if(user):
|
|
if(user):
|
|
|
- if(not re.search('\.', ip)):
|
|
|
|
|
|
|
+ if(not re.search('(\.|:)', ip)):
|
|
|
conn.close()
|
|
conn.close()
|
|
|
return(redirect('/logout'))
|
|
return(redirect('/logout'))
|
|
|
elif(bcrypt.checkpw(bytes(request.forms.pw, 'utf-8'), bytes(user[0]['pw'], 'utf-8'))):
|
|
elif(bcrypt.checkpw(bytes(request.forms.pw, 'utf-8'), bytes(user[0]['pw'], 'utf-8'))):
|
|
@@ -2052,7 +2052,7 @@ def change_password():
|
|
|
conn.close()
|
|
conn.close()
|
|
|
return(redirect('/ban'))
|
|
return(redirect('/ban'))
|
|
|
else:
|
|
else:
|
|
|
- if(not re.search('\.', ip)):
|
|
|
|
|
|
|
+ if(not re.search('(\.|:)', ip)):
|
|
|
conn.close()
|
|
conn.close()
|
|
|
return(redirect('/logout'))
|
|
return(redirect('/logout'))
|
|
|
else:
|
|
else:
|
|
@@ -2655,7 +2655,7 @@ def custom_css():
|
|
|
session = request.environ.get('beaker.session')
|
|
session = request.environ.get('beaker.session')
|
|
|
ip = ip_check()
|
|
ip = ip_check()
|
|
|
if(request.method == 'POST'):
|
|
if(request.method == 'POST'):
|
|
|
- if(not re.search('\.', ip)):
|
|
|
|
|
|
|
+ if(not re.search('(\.|:)', ip)):
|
|
|
curs.execute("select * from custom where user = '" + db_pas(ip) + "'")
|
|
curs.execute("select * from custom where user = '" + db_pas(ip) + "'")
|
|
|
css_data = curs.fetchall()
|
|
css_data = curs.fetchall()
|
|
|
if(css_data):
|
|
if(css_data):
|
|
@@ -2669,7 +2669,7 @@ def custom_css():
|
|
|
conn.close()
|
|
conn.close()
|
|
|
return(redirect('/user'))
|
|
return(redirect('/user'))
|
|
|
else:
|
|
else:
|
|
|
- if(not re.search('\.', ip)):
|
|
|
|
|
|
|
+ if(not re.search('(\.|:)', ip)):
|
|
|
start = ''
|
|
start = ''
|
|
|
curs.execute("select * from custom where user = '" + db_pas(ip) + "'")
|
|
curs.execute("select * from custom where user = '" + db_pas(ip) + "'")
|
|
|
css_data = curs.fetchall()
|
|
css_data = curs.fetchall()
|