Redirect if non-staff access the search functions

This commit is contained in:
2011-04-10 12:00:48 +01:00
parent 9783844b15
commit 13bb83e7a9

View File

@@ -155,6 +155,9 @@ def service_reset(request, serviceid=0):
def user_view(request, username=None):
""" View a user's profile as a admin """
if not request.user.is_staff:
return redirect('sso.views.profile')
if username:
try:
user = User.objects.get(username=username)
@@ -181,6 +184,9 @@ def user_lookup(request):
form = UserLookupForm()
if not request.user.is_staff:
return redirect('sso.views.profile')
if request.method == 'POST':
form = UserLookupForm(request.POST)
if form.is_valid():