diff --git a/alkatorapi/views.py b/alkatorapi/views.py index 01f2a74..e1765ec 100644 --- a/alkatorapi/views.py +++ b/alkatorapi/views.py @@ -183,6 +183,7 @@ def login_status(request): @csrf_exempt def change_racer(request): try: + racer = Racer.objects.get(request.POST['invoice_id']) if request.user != racer.profile.user: return HttpResponse('{"reason":"Nedostatečná práva!"}', status=400, content_type='application/json') if date.today() >= DEADLINE: @@ -199,7 +200,6 @@ def change_racer(request): return HttpResponse('{"reason":"Opravdu vám je 100 let?"}', status=400, content_type='application/json') except: return HttpResponse('{"reason":"Špatný formát datu narození!"}', status=400, content_type='application/json') - racer = Racer.objects.get(request.POST['invoice_id']) racer.first_name = request.POST['first_name'] racer.last_name = request.POST['last_name'] racer.email = request.POST['email']