[FIX] potential bug in server-side web framework, now forbids users to call method when not authentified

bzr revid: nicolas.vanhoren@openerp.com-20131018125727-qtkzkiwkhw4z78kr
This commit is contained in:
niv-openerp 2013-10-18 14:57:27 +02:00
parent c348a2f4cd
commit 7636d71dfc
1 changed files with 2 additions and 0 deletions

View File

@ -189,6 +189,8 @@ class WebRequest(object):
def auth_method_user():
request.uid = request.session.uid
if not request.uid:
raise SessionExpiredException("Session expired")
def auth_method_admin():
if not request.db: