security check for user creation

This commit is contained in:
Usman Nasir
2020-01-21 19:53:58 +05:00
parent ec644f12ee
commit 2756293046

View File

@@ -91,7 +91,6 @@ def apiAccess(request):
logging.CyberCPLogFileWriter.writeToFile(str(msg))
return redirect(loadLoginPage)
def saveChangesAPIAccess(request):
try:
userID = request.session['userID']
@@ -123,7 +122,6 @@ def saveChangesAPIAccess(request):
json_data = json.dumps(finalResponse)
return HttpResponse(json_data)
def submitUserCreation(request):
try:
@@ -200,6 +198,13 @@ def submitUserCreation(request):
newAdmin.save()
elif currentACL['createNewUser'] == 1:
if selectedACL != 'user':
data_ret = {'status': 0, 'createStatus': 0,
'error_message': "You are not authorized to access this resource."}
final_json = json.dumps(data_ret)
return HttpResponse(final_json)
newAdmin = Administrator(firstName=firstName,
lastName=lastName,
email=email,