changeset 2626:4abce2c11c5f beta

My account pages shouldn't be accessible by anonymous users
author Marcin Kuzminski <marcin@python-works.com>
date Mon, 16 Jul 2012 23:44:50 +0200
parents fc19979a8421
children 6bd62617b99f
files rhodecode/controllers/admin/settings.py
diffstat 1 files changed, 5 insertions(+), 1 deletions(-) [+]
line wrap: on
line diff
--- a/rhodecode/controllers/admin/settings.py	Mon Jul 16 23:41:54 2012 +0200
+++ b/rhodecode/controllers/admin/settings.py	Mon Jul 16 23:44:50 2012 +0200
@@ -350,6 +350,7 @@
         )
         return render('admin/users/user_edit_my_account.html')
 
+    @NotAnonymous()
     def my_account_update(self):
         """PUT /_admin/my_account_update: Update an existing item"""
         # Forms posted to this method should contain a hidden field:
@@ -385,7 +386,8 @@
                     % form_result.get('username'), category='error')
 
         return redirect(url('my_account'))
-
+    
+    @NotAnonymous()
     def my_account_my_repos(self):
         all_repos = self.sa.query(Repository)\
             .filter(Repository.user_id == self.rhodecode_user.user_id)\
@@ -394,6 +396,7 @@
         c.user_repos = ScmModel().get_repos(all_repos)
         return render('admin/users/user_edit_my_account_repos.html')
 
+    @NotAnonymous()
     def my_account_my_pullrequests(self):
         c.my_pull_requests = PullRequest.query()\
                                 .filter(PullRequest.user_id==
@@ -420,6 +423,7 @@
 
         return render('admin/repos/repo_add_create_repository.html')
 
+    @NotAnonymous()
     def get_hg_ui_settings(self):
         ret = self.sa.query(RhodeCodeUi).all()