fix: don't expose scope for non-admin users
parent
c1987237d0
commit
0942fc7042
|
@ -94,6 +94,9 @@ var userGetHandler = withSelfOrAdmin(func(w http.ResponseWriter, r *http.Request
|
|||
}
|
||||
|
||||
u.Password = ""
|
||||
if !u.Perm.Admin {
|
||||
u.Scope = ""
|
||||
}
|
||||
return renderJSON(w, r, u)
|
||||
})
|
||||
|
||||
|
|
Loading…
Reference in New Issue