Skip to content
Snippets Groups Projects
Commit 01444f7d authored by chzesa's avatar chzesa
Browse files

Handle duplicate username on server side so this contrived vulnerability makes sense

parent bbf653ef
Branches master
No related tags found
No related merge requests found
......@@ -10,8 +10,6 @@
headers: { from:'{{user}}' }
}).then(r => r.json()).then(v => {
v.users.forEach(u => {
if (u == '{{user}}')
return;
let p = document.createElement(`p`)
let e = document.createElement(`a`);
p.appendChild(e)
......
......@@ -17,7 +17,7 @@ def getUsers(request):
return JsonResponse()
with connection.cursor() as cursor:
users = cursor.execute("SELECT username FROM auth_user WHERE id != '%s'" % (request.GET.get('from')))
users = cursor.execute("SELECT username FROM auth_user WHERE username != '%s'" % (request.headers.get('from')))
r = []
for u in users:
......
0% Loading or .
You are about to add 0 people to the discussion. Proceed with caution.
Please register or to comment