fix: don't expose scope for non-admin users
parent
c1987237d0
commit
0942fc7042
|
@ -94,6 +94,9 @@ var userGetHandler = withSelfOrAdmin(func(w http.ResponseWriter, r *http.Request
|
||||||
}
|
}
|
||||||
|
|
||||||
u.Password = ""
|
u.Password = ""
|
||||||
|
if !u.Perm.Admin {
|
||||||
|
u.Scope = ""
|
||||||
|
}
|
||||||
return renderJSON(w, r, u)
|
return renderJSON(w, r, u)
|
||||||
})
|
})
|
||||||
|
|
||||||
|
|
Loading…
Reference in New Issue