瀏覽代碼

refactor: Excludes user credentials by default

Owen Diffey 4 周之前
父節點
當前提交
d6bf01329a
共有 1 個文件被更改,包括 13 次插入1 次删除
  1. 13 1
      backend/src/modules/DataModule/models/User.ts

+ 13 - 1
backend/src/modules/DataModule/models/User.ts

@@ -293,7 +293,19 @@ export const schema = {
 	}
 };
 
-export const options = {};
+export const options = {
+	defaultScope: {
+		attributes: {
+			exclude: [
+				"emailVerificationToken",
+				"password",
+				"passwordResetCode",
+				"passwordSetCode",
+				"githubAccessToken"
+			]
+		}
+	}
+};
 
 export const setup = async () => {
 	User.hasMany(Session, {