Check if user is allowed to edit

This commit is contained in:
Feliciaan De Palmenaer 2015-06-04 21:36:57 +02:00
parent 333a7ec5ec
commit 3d5f6ef1ae

View file

@ -53,6 +53,8 @@ def order(id, form=None):
@login_required @login_required
def order_edit(id): def order_edit(id):
order = Order.query.filter(Order.id == id).first() order = Order.query.filter(Order.id == id).first()
if current_user.id is not order.courrier_id and not current_user.is_admin():
abort(401)
if order is None: if order is None:
abort(404) abort(404)
orderForm = OrderForm(obj=order) orderForm = OrderForm(obj=order)