People
Base element CSP bypass
Description
Solution
@main.route('/flag')
def flag():
if request.cookies.get('admin_token') == admin_token:
return os.getenv('FLAG') or 'flag{flag_not_set}'
else:
abort(403)
@main.route('/report/<user_id>', methods=['POST'])
@limiter.limit("2/2 minute")
def report(user_id):
user = User.query.get(user_id)
q.enqueue(visit, user.id, admin_token)
flash("Thank you, an admin will review your report shortly.", "success")
return redirect(url_for('main.profile', user_id=user_id))
Last updated