Browse Source

Prevent sending private messages to banned users

merge-requests/53/head
Deimos 6 years ago
parent
commit
24f2ad47f4
  1. 4
      tildes/tildes/models/user/user.py

4
tildes/tildes/models/user/user.py

@ -137,7 +137,9 @@ class User(DatabaseModel):
acl.append((Allow, Everyone, "view"))
# message:
# - anyone can message a user except themself
# - banned users can't be messaged
# - otherwise, anyone can message a user except themself
if not self.is_banned:
acl.append((Deny, self.user_id, "message"))
acl.append((Allow, Authenticated, "message"))

Loading…
Cancel
Save