explicitly set permissions to false for anonymous users

This commit is contained in:
Patrick Jentsch 2024-04-11 15:46:58 +02:00
parent ccf484c9bc
commit 8f960cf359

View File

@ -1,4 +1,5 @@
from enum import Enum
from flask_login import AnonymousUserMixin
from app import db, login, mail, socketio
from app.email import create_message
from .avatar import *
@ -141,6 +142,16 @@ def job_after_update_handler(mapper, connection, job):
mail.send(msg)
class AnonymousUser(AnonymousUserMixin):
def can(self, permissions):
return False
@property
def is_administrator(self):
return False
login.anonymous_user = AnonymousUser
@login.user_loader
def load_user(user_id):