Hide ‘back to …’ link if it’s not your service

This can happen if you click a link for a service you don’t have access
to. We shouldn’t show the back to service link in this case because:
- you shouldn’t be able to find out the service’s name from just knowing
  the link
- if you click the link you only get a `403` anyway
This commit is contained in:
Chris Hill-Scott
2019-01-15 17:31:55 +00:00
parent 7c92847b85
commit 558ae87baa
4 changed files with 57 additions and 3 deletions

View File

@@ -2,7 +2,7 @@
{% block fullwidth_content %}
<div id="content">
{% if current_service and current_user.is_authenticated %}
{% if current_service and current_user.is_authenticated and current_user.belongs_to_service(current_service.id) %}
<div class="navigation-service">
<a href="{{ url_for('main.show_accounts_or_dashboard') }}">Back to {{ current_service.name }}</a>
</div>