From 19034f5b69b904a8e93db8e8a7de308f0085251a Mon Sep 17 00:00:00 2001 From: Noah Petherbridge Date: Fri, 28 Mar 2014 01:24:41 -0700 Subject: [PATCH] Only admins can delete blog posts --- rophako/modules/blog.py | 1 + 1 file changed, 1 insertion(+) diff --git a/rophako/modules/blog.py b/rophako/modules/blog.py index 6c755e6..d2eb511 100644 --- a/rophako/modules/blog.py +++ b/rophako/modules/blog.py @@ -192,6 +192,7 @@ def update(): @mod.route("/delete", methods=["GET", "POST"]) +@admin_required def delete(): """Delete a blog post.""" post_id = request.args.get("id")