Skip to content

Commit e3e3219

Browse files
author
Gaotax2006
committed
fix(api): omit password fields from user creation response (#8215)
1 parent e1bbd06 commit e3e3219

1 file changed

Lines changed: 2 additions & 1 deletion

File tree

apps/api/src/services/userService.js

Lines changed: 2 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -5,7 +5,8 @@ export async function listUsers() {
55
}
66

77
export async function createUser(payload) {
8-
const user = { id: `usr_${Date.now()}`, ...payload };
8+
const { password: _ignoredPassword, passwordHash: _ignoredHash, ...safePayload } = payload || {};
9+
const user = { id: `usr_${Date.now()}`, ...safePayload };
910
users.push(user);
1011
return user;
1112
}

0 commit comments

Comments
 (0)