-
Notifications
You must be signed in to change notification settings - Fork 2
Open
Description
Should probably extend CurrentUserSerializer instead of BasicUserSerializer to prevent leakage of user's settings (nearataTwoFactorCanEnable, nearataTwoFactorAppEnabled) to others via app.forum.store.data.users
flarum-ext-twofactor/extend.php
Line 42 in 7525ccd
| (new Extend\ApiSerializer(BasicUserSerializer::class)) |
Metadata
Metadata
Assignees
Labels
No labels