def user(userid):
if int(userid) != get_userid():
abort(401)
- groups = query_db('select * from groups join user_group on id=id_group where id_user = ?', userid)
+ groups = query_db('select * from groups join user_group on id=id_group where id_user = ?', (userid,))
return render_template('user.html', groups=groups)
@app.route('/user/settings/<userid>', methods=['GET', 'POST'])