瀏覽代碼

Update SiteController, return 404 for users attempting to view their own Follow Intent

Daniel Supernault 5 年之前
父節點
當前提交
8e9b544f50
共有 1 個文件被更改,包括 1 次插入0 次删除
  1. 1 0
      app/Http/Controllers/SiteController.php

+ 1 - 0
app/Http/Controllers/SiteController.php

@@ -116,6 +116,7 @@ class SiteController extends Controller
         ]);
         ]);
         $profile = Profile::whereUsername($request->input('user'))->firstOrFail();
         $profile = Profile::whereUsername($request->input('user'))->firstOrFail();
         $user = $request->user();
         $user = $request->user();
+        abort_if($profile->id == $user->profile_id, 404);
         $following = $user != null ? FollowerService::follows($user->profile_id, $profile->id) : false;
         $following = $user != null ? FollowerService::follows($user->profile_id, $profile->id) : false;
         return view('site.intents.follow', compact('profile', 'user', 'following'));
         return view('site.intents.follow', compact('profile', 'user', 'following'));
     }
     }