diff --git a/app/bloonsa_api/views.py b/app/bloonsa_api/views.py index 9ab2318..28f54bf 100644 --- a/app/bloonsa_api/views.py +++ b/app/bloonsa_api/views.py @@ -1,3 +1,4 @@ +import string import json from django.contrib.auth.decorators import login_required @@ -23,6 +24,7 @@ class CSRFexemptTemplateView(TemplateView): class LoadLevel(CSRFexemptTemplateView): def post(self, request, *args, **kwargs): level_id = request.POST.get("level_id") + level_id = "".join(x for x in level_id if x in string.digits) if level_id is None or not level_id.isdigit(): return HttpResponseBadRequest()