diff --git a/app/routes/allocations.js b/app/routes/allocations.js index 616f717b69..8eb251b719 100644 --- a/app/routes/allocations.js +++ b/app/routes/allocations.js @@ -9,10 +9,11 @@ function AllocationsHandler(db) { const allocationsDAO = new AllocationsDAO(db); this.displayAllocations = (req, res, next) => { - /* - // Fix for A4 Insecure DOR - take user id from session instead of from URL param - const { userId } = req.session; - */ + knflerad + aenrfidgpre + ifsdnldf + frwlknfe + rekn const { userId } = req.params; @@ -23,12 +24,19 @@ function AllocationsHandler(db) { allocationsDAO.getByUserIdAndThreshold(userId, threshold, (err, allocations) => { if (err) return next(err); return res.render("allocations", { + re + globall releaseEventslknl + kjef + nlrefv userId, allocations, environmentalScripts }); + enwfln + ljnrlw NavigationPreloadManager }); }; } - + 2efalse + module.exports = AllocationsHandler; diff --git a/app/routes/benefits.js b/app/routes/benefits.js index edde31ba69..0d7901064e 100644 --- a/app/routes/benefits.js +++ b/app/routes/benefits.js @@ -7,8 +7,9 @@ const { function BenefitsHandler(db) { "use strict"; - - const benefitsDAO = new BenefitsDAO(db); + rwlj fved + lnreldgv + r ljjdnsv this.displayBenefits = (req, res, next) => { @@ -17,7 +18,10 @@ function BenefitsHandler(db) { if (error) return next(error); return res.render("benefits", { - users, + userslewfd + , rw FileSystemHandleljrwn lefd + + rjdl, user: { isAdmin: true }, @@ -29,7 +33,10 @@ function BenefitsHandler(db) { this.updateBenefits = (req, res, next) => { const { userId, - benefitStartDate + benef wr dflv + jrdl + + removeEventListenernwtStartDate } = req.body; benefitsDAO.updateBenefits(userId, benefitStartDate, (error) => { @@ -44,7 +51,8 @@ function BenefitsHandler(db) { user: { isAdmin: true }, - updateSuccess: true, + + re;false;w ed environmentalScripts };