fixed vulnerabilities on deleting release (#399)

This commit is contained in:
Lunny Xiao 2016-12-16 19:42:39 +08:00 committed by GitHub
parent 8aeeed0a23
commit 15c3d14d55
2 changed files with 9 additions and 2 deletions

View file

@ -296,7 +296,7 @@ func EditReleasePost(ctx *context.Context, form auth.EditReleaseForm) {
// DeleteRelease delete a release
func DeleteRelease(ctx *context.Context) {
if err := models.DeleteReleaseByID(ctx.QueryInt64("id")); err != nil {
if err := models.DeleteReleaseByID(ctx.QueryInt64("id"), ctx.User); err != nil {
ctx.Flash.Error("DeleteReleaseByID: " + err.Error())
} else {
ctx.Flash.Success(ctx.Tr("repo.release.deletion_success"))