]> git.openstreetmap.org Git - osqa.git/blobdiff - forum/views/users.py
fix breach in award points that allows user to award infinite points / extra fix
[osqa.git] / forum / views / users.py
index 786320ca9608b08414e1eef47ec12642e5331316..adf9b5959d2f9ebca8a31f6b9077c33116dc487a 100644 (file)
@@ -220,7 +220,7 @@ def award_points(request, id):
 
     extra = dict(message=request.POST.get('message', ''), awarding_user=request.user.id, value=points)
 
-    BonusRepAction(user=user, extra=extra).save(data=dict(value=points, affected=user))
+    BonusRepAction(user=request.user, extra=extra).save(data=dict(value=points, affected=user))
 
     return {'commands': {
             'update_profile_karma': [user.reputation]