fixed a bug that allowed user bios to be hijacked
This commit is contained in:
parent
2cfb5e6062
commit
902ef5ed0c
1 changed files with 2 additions and 1 deletions
|
@ -9,9 +9,10 @@ const router = Router();
|
|||
//todo: fix jank
|
||||
|
||||
router.get('/:username', async (req, res, next) => {
|
||||
let topComment = await db.all('SELECT * FROM feeder WHERE parentType = ? AND parentId = ? ORDER BY sortId ASC LIMIT ? OFFSET ?', [
|
||||
let topComment = await db.all('SELECT * FROM feeder WHERE parentType = ? AND parentId = ? AND childId in (SELECT id FROM comment WHERE username = ?) ORDER BY sortId ASC LIMIT ? OFFSET ?', [
|
||||
'users',
|
||||
req.params.username,
|
||||
req.params.username,
|
||||
1,
|
||||
0
|
||||
]);
|
||||
|
|
Loading…
Add table
Add a link
Reference in a new issue