fixed a bug that allowed user bios to be hijacked
This commit is contained in:
parent
2cfb5e6062
commit
902ef5ed0c
1 changed files with 2 additions and 1 deletions
|
@ -9,9 +9,10 @@ const router = Router();
|
||||||
//todo: fix jank
|
//todo: fix jank
|
||||||
|
|
||||||
router.get('/:username', async (req, res, next) => {
|
router.get('/:username', async (req, res, next) => {
|
||||||
let topComment = await db.all('SELECT * FROM feeder WHERE parentType = ? AND parentId = ? ORDER BY sortId ASC LIMIT ? OFFSET ?', [
|
let topComment = await db.all('SELECT * FROM feeder WHERE parentType = ? AND parentId = ? AND childId in (SELECT id FROM comment WHERE username = ?) ORDER BY sortId ASC LIMIT ? OFFSET ?', [
|
||||||
'users',
|
'users',
|
||||||
req.params.username,
|
req.params.username,
|
||||||
|
req.params.username,
|
||||||
1,
|
1,
|
||||||
0
|
0
|
||||||
]);
|
]);
|
||||||
|
|
Loading…
Add table
Add a link
Reference in a new issue