Check if user is allowed to edit
This commit is contained in:
parent
333a7ec5ec
commit
3d5f6ef1ae
1 changed files with 2 additions and 0 deletions
|
@ -53,6 +53,8 @@ def order(id, form=None):
|
|||
@login_required
|
||||
def order_edit(id):
|
||||
order = Order.query.filter(Order.id == id).first()
|
||||
if current_user.id is not order.courrier_id and not current_user.is_admin():
|
||||
abort(401)
|
||||
if order is None:
|
||||
abort(404)
|
||||
orderForm = OrderForm(obj=order)
|
||||
|
|
Loading…
Reference in a new issue