summaryrefslogtreecommitdiff
path: root/chimere/main/views.py
diff options
context:
space:
mode:
authorÉtienne Loks <etienne.loks@peacefrogs.net>2010-11-27 19:09:37 +0100
committerÉtienne Loks <etienne.loks@peacefrogs.net>2010-11-27 19:09:37 +0100
commit9938ec566e87fe66cd8e91576fefbfbcadddd9c3 (patch)
tree50aba593f62f4b05cd23ecb2be4395a7ffd2b1bb /chimere/main/views.py
parent30c05dafd18c1c6670453a0fecbedef21cae9ddf (diff)
downloadChimère-9938ec566e87fe66cd8e91576fefbfbcadddd9c3.tar.bz2
Chimère-9938ec566e87fe66cd8e91576fefbfbcadddd9c3.zip
Use a sanitize filter to correct a security issue (closes #283)
Diffstat (limited to 'chimere/main/views.py')
-rw-r--r--chimere/main/views.py2
1 files changed, 1 insertions, 1 deletions
diff --git a/chimere/main/views.py b/chimere/main/views.py
index d8e9719..5d13dcb 100644
--- a/chimere/main/views.py
+++ b/chimere/main/views.py
@@ -243,7 +243,7 @@ def getDetail(request, area_name, marker_id):
Get the detail for a marker
'''
try:
- marker = Marker.objects.filter(id=int(marker_id), status='A')[0]
+ marker = Marker.objects.filter(id=int(marker_id), status__in=['A', 'S'])[0]
except (ValueError, IndexError):
return HttpResponse('no results')
response_dct = get_base_response()