ajout de sécurité pour le URL
This commit is contained in:
@@ -175,6 +175,33 @@ def view_tryout(tryout_id):
|
||||
Response: Rendered tryout detail template.
|
||||
"""
|
||||
tryout = Tryout.query.get_or_404(tryout_id)
|
||||
|
||||
# Check if user has permission to view this tryout
|
||||
can_view = False
|
||||
if current_user.role == 'president':
|
||||
can_view = True
|
||||
elif current_user.role == 'manager' and tryout.created_by == current_user.id:
|
||||
can_view = True
|
||||
elif current_user.role == 'coach':
|
||||
org_team = OrgTeam.query.filter_by(coach_id=current_user.id).first()
|
||||
if org_team and tryout.target_org_team_id == org_team.id:
|
||||
can_view = True
|
||||
elif current_user.role == 'player':
|
||||
is_registered = TryoutRegistration.query.filter_by(
|
||||
tryout_id=tryout_id, player_id=current_user.id
|
||||
).first() is not None
|
||||
player_in_match = MatchParticipant.query.join(Match).filter(
|
||||
MatchParticipant.player_id == current_user.id,
|
||||
Match.tryout_id == tryout_id
|
||||
).first() is not None
|
||||
can_view = is_registered or player_in_match
|
||||
elif current_user.role == 'scout':
|
||||
can_view = True
|
||||
|
||||
if not can_view:
|
||||
flash('You do not have permission to view this tryout.', 'danger')
|
||||
return redirect(url_for('tryouts.list_tryouts'))
|
||||
|
||||
registrations = TryoutRegistration.query.filter_by(tryout_id=tryout_id).all()
|
||||
registered_players = [User.query.get(r.player_id) for r in registrations if r.player_id]
|
||||
evaluations = Evaluation.query.filter_by(tryout_id=tryout_id).all()
|
||||
|
||||
Reference in New Issue
Block a user