This commit is contained in:
Baris Soner Usakli
2013-09-19 20:43:56 -04:00
parent 21efda4a84
commit 6be5bcc4c8
3 changed files with 9 additions and 5 deletions

View File

@@ -332,12 +332,14 @@ var user = require('./../user.js'),
return;
}
if (uid !== callerUID || callerUID === '0') {
if (uid != callerUID || callerUID == '0') {
res.json(403, {
error: 'Not allowed!'
});
return;
}
user.getUserFields(uid, ['username', 'userslug', 'showemail'], function(err, userData) {
if (err)
return next(err);
@@ -368,7 +370,7 @@ var user = require('./../user.js'),
return;
}
if (uid !== callerUID || callerUID === '0') {
if (uid != callerUID || callerUID == '0') {
res.json(403, {
error: 'Not allowed!'
});
@@ -491,13 +493,13 @@ var user = require('./../user.js'),
}
function canSeeEmail() {
return callerUID === uid || (data.email && (data.showemail && data.showemail === "1"));
return callerUID == uid || (data.email && (data.showemail && data.showemail === "1"));
}
if (!canSeeEmail())
data.email = "";
if (callerUID === uid && (!data.showemail || data.showemail === "0"))
if (callerUID == uid && (!data.showemail || data.showemail === "0"))
data.emailClass = "";
else
data.emailClass = "hide";