Commit 9d419b4
authored
fix: user sanitization should clean up email change info too (#1759)
The `sanitizeUser` function did not cleanup the **EmailChange** and
**EmailChangeSentAt** properties on a User. If a User had a pending
email address change, the new address could be leaked via a crafted
`signUp` request.1 parent 7009202 commit 9d419b4
1 file changed
+2
-2
lines changed| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
336 | 336 | | |
337 | 337 | | |
338 | 338 | | |
339 | | - | |
| 339 | + | |
340 | 340 | | |
341 | | - | |
| 341 | + | |
342 | 342 | | |
343 | 343 | | |
344 | 344 | | |
| |||
0 commit comments