diff --git a/src/webserver.js b/src/webserver.js index fb0d29bb44..2f6fddde44 100644 --- a/src/webserver.js +++ b/src/webserver.js @@ -336,7 +336,7 @@ passport.deserializeUser(function(uid, done) { if(!req.user) return res.redirect('/403'); - console.log(req.body.uid); + if(req.user.uid !== req.body.uid) return res.redirect('/');