fixed a bug that allowed user bios to be hijacked

This commit is contained in:
biglyderv 2025-05-28 00:44:36 -04:00
parent 2cfb5e6062
commit 902ef5ed0c
Signed by: biglyderv
GPG key ID: 0E2EB0B4CD7397B5

View file

@ -9,9 +9,10 @@ const router = Router();
//todo: fix jank
router.get('/:username', async (req, res, next) => {
let topComment = await db.all('SELECT * FROM feeder WHERE parentType = ? AND parentId = ? ORDER BY sortId ASC LIMIT ? OFFSET ?', [
let topComment = await db.all('SELECT * FROM feeder WHERE parentType = ? AND parentId = ? AND childId in (SELECT id FROM comment WHERE username = ?) ORDER BY sortId ASC LIMIT ? OFFSET ?', [
'users',
req.params.username,
req.params.username,
1,
0
]);