Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

fix: user sanitization should clean up email change info too #1759

Merged
merged 1 commit into from
Sep 3, 2024

Commits on Sep 3, 2024

  1. fix: sanitizeUser function should clean EmailChange

    The sanitizeUser function did not cleanup the EmailChange and
    EmailChangeSentAt properties on a User. If a User had a pending
    email address change, the new address could be leaked via a crafted
    signUp request.
    staaldraad committed Sep 3, 2024
    Configuration menu
    Copy the full SHA
    7f084b2 View commit details
    Browse the repository at this point in the history