Explorar el Código

Update SiteController, return 404 for users attempting to view their own Follow Intent

Daniel Supernault hace 5 años
padre
commit
8e9b544f50
Se han modificado 1 ficheros con 1 adiciones y 0 borrados
  1. 1 0
      app/Http/Controllers/SiteController.php

+ 1 - 0
app/Http/Controllers/SiteController.php

@@ -116,6 +116,7 @@ class SiteController extends Controller
         ]);
         $profile = Profile::whereUsername($request->input('user'))->firstOrFail();
         $user = $request->user();
+        abort_if($profile->id == $user->profile_id, 404);
         $following = $user != null ? FollowerService::follows($user->profile_id, $profile->id) : false;
         return view('site.intents.follow', compact('profile', 'user', 'following'));
     }