[extensions-web] Don't allow users to grab all extensions by using no query params
- From: Jasper St. Pierre <jstpierre src gnome org>
- To: commits-list gnome org
- Cc:
- Subject: [extensions-web] Don't allow users to grab all extensions by using no query params
- Date: Thu, 27 Oct 2011 21:37:49 +0000 (UTC)
commit 76caf730bde4703b9b782b9c5ff84b2a825365b6
Author: Jasper St. Pierre <jstpierre mecheye net>
Date: Thu Oct 27 17:35:48 2011 -0400
Don't allow users to grab all extensions by using no query params
sweettooth/extensions/views.py | 3 +++
1 files changed, 3 insertions(+), 0 deletions(-)
---
diff --git a/sweettooth/extensions/views.py b/sweettooth/extensions/views.py
index e2dea58..52e057c 100644
--- a/sweettooth/extensions/views.py
+++ b/sweettooth/extensions/views.py
@@ -180,6 +180,9 @@ def ajax_query_view(request):
if uuids:
query_params['uuid__in'] = uuids
+ if not query_params:
+ raise Http404()
+
extensions = models.Extension.objects.filter(**query_params)
return [ajax_details(e) for e in extensions]
[
Date Prev][
Date Next] [
Thread Prev][
Thread Next]
[
Thread Index]
[
Date Index]
[
Author Index]