From 416655764d26ef3c90f6f223b8be092d15a05188 Mon Sep 17 00:00:00 2001 From: Dominik Picheta Date: Thu, 17 May 2018 19:54:15 +0100 Subject: [PATCH] Ensure deleted posts and threads are not accessible. --- forum.nim | 7 ++++--- 1 file changed, 4 insertions(+), 3 deletions(-) diff --git a/forum.nim b/forum.nim index 7273959..27e2a73 100644 --- a/forum.nim +++ b/forum.nim @@ -1148,7 +1148,8 @@ routes: const threadsQuery = sql"""select id, name, views, strftime('%s', modified) from thread - order by modified desc limit ?, ?;""" # TODO: Moderation + where isDeleted = 0 + order by modified desc limit ?, ?;""" let thrCount = getValue(db, sql"select count(*) from thread;").parseInt() let moreCount = max(0, thrCount - (start + count)) @@ -1171,7 +1172,7 @@ routes: const threadsQuery = sql"""select id, name, views, strftime('%s', modified) from thread - where id = ?;""" + where id = ? and isDeleted = 0;""" let threadRow = getRow(db, threadsQuery, id) let thread = selectThread(threadRow) @@ -1181,7 +1182,7 @@ routes: """select p.id, p.content, strftime('%s', p.creation), p.author, u.name, u.email, strftime('%s', u.lastOnline), u.status from post p, person u - where u.id = p.author and p.thread = ? + where u.id = p.author and p.thread = ? and p.isDeleted = 0 order by p.id""" )