Skip to content

Commit

Permalink
Merge pull request #1655 from ConductionNL/fix/login-response
Browse files Browse the repository at this point in the history
Let's not show api-keys in the login api-call response
  • Loading branch information
WilcoLouwerse authored Jun 28, 2024
2 parents 50382d0 + 03cd476 commit ab686c8
Showing 1 changed file with 5 additions and 2 deletions.
7 changes: 5 additions & 2 deletions api/src/Controller/UserController.php
Original file line number Diff line number Diff line change
Expand Up @@ -275,14 +275,17 @@ private function cleanupLoginResponse(array $userArray): array
if (isset($userArray['organization']['users']) === true) {
unset($userArray['organization']['users']);
}

if (isset($userArray['organization']['applications']) === true) {
foreach ($userArray['organization']['applications'] as &$application) {
unset($application['organization']);
unset($application['secret'], $application['organization']);
}
}

foreach ($userArray['applications'] as &$application) {
unset($application['organization']);
unset($application['secret'], $application['organization']);
}

foreach ($userArray['securityGroups'] as &$securityGroup) {
unset($securityGroup['users']);
unset($securityGroup['parent']);
Expand Down

0 comments on commit ab686c8

Please sign in to comment.