Skip to content

Commit a002ad0

Browse files
committed
fix(security): remove unconfirmed_email from /whoami for apps
1 parent b737570 commit a002ad0

File tree

1 file changed

+1
-0
lines changed

1 file changed

+1
-0
lines changed

src/backend/src/routers/whoami.js

+1
Original file line numberDiff line numberDiff line change
@@ -73,6 +73,7 @@ const WHOAMI_GET = eggspress('/whoami', {
7373
// delete details.username;
7474
// delete details.uuid;
7575
delete details.email;
76+
delete details.unconfirmed_email;
7677
delete details.desktop_bg_url;
7778
delete details.desktop_bg_color;
7879
delete details.desktop_bg_fit;

0 commit comments

Comments
 (0)