diff --git a/public/templates/accountedit.tpl b/public/templates/accountedit.tpl index 33e4719432..63f393e5db 100644 --- a/public/templates/accountedit.tpl +++ b/public/templates/accountedit.tpl @@ -76,7 +76,7 @@ $(document).ready(function(){ $('#submitBtn').on('click',function(){ - + alert('click'); var userData = { uid:$('#inputUID').val(), email:$('#inputEmail').val(), @@ -89,7 +89,7 @@ $.post('/edituser', userData, function(data) { - + alert('fail'); } ); diff --git a/src/webserver.js b/src/webserver.js index e9280cdb5d..e1e5166012 100644 --- a/src/webserver.js +++ b/src/webserver.js @@ -333,11 +333,11 @@ passport.deserializeUser(function(uid, done) { }); app.post('/edituser', function(req, res){ - + if(!req.user) return res.redirect('/403'); - if(req.user.uid !== req.body.uid) + if(req.user.uid != req.body.uid) return res.redirect('/'); user.updateUserFields(req.user.uid, req.body);