Skip to content
Snippets Groups Projects
Commit ebbe181a authored by ale's avatar ale
Browse files

additional safeguards

parent b0aa9370
No related branches found
No related tags found
No related merge requests found
...@@ -119,7 +119,7 @@ def user_send_invite(): ...@@ -119,7 +119,7 @@ def user_send_invite():
def user_activate(token): def user_activate(token):
email = request.args.get('email') email = request.args.get('email')
user = User.query.filter_by(activation_token=token).first() user = User.query.filter_by(activation_token=token).first()
if not user or user.email != email: if not user or user.active or user.email != email:
abort(404) abort(404)
session['userid'] = user.id session['userid'] = user.id
user.active = True user.active = True
......
0% Loading or .
You are about to add 0 people to the discussion. Proceed with caution.
Please register or to comment