Skip to content

Commit

Permalink
Merge pull request #4880 from sbwalker/dev
Browse files Browse the repository at this point in the history
User Settings should only be accessible to individual users or administrators
  • Loading branch information
sbwalker authored Nov 27, 2024
2 parents 2441647 + d96286d commit 497b255
Showing 1 changed file with 1 addition and 14 deletions.
15 changes: 1 addition & 14 deletions Oqtane.Server/Controllers/UserController.cs
Original file line number Diff line number Diff line change
Expand Up @@ -145,20 +145,7 @@ private User Filter(User user)
filtered.DeletedBy = user.DeletedBy;
filtered.DeletedOn = user.DeletedOn;
filtered.IsDeleted = user.IsDeleted;
}

// if authenticated user is accessing their own user account
if (_userPermissions.GetUser(User).UserId == user.UserId)
{
// include all settings
filtered.Settings = user.Settings;
}
else
{
// include only public settings
filtered.Settings = _settings.GetSettings(EntityNames.User, user.UserId)
.Where(item => !item.IsPrivate)
.ToDictionary(setting => setting.SettingName, setting => setting.SettingValue);
filtered.Settings = user.Settings; // include all settings
}
}

Expand Down

0 comments on commit 497b255

Please sign in to comment.