Skip to content

Commit b9b43be

Browse files
committed
WebUserServive don't expose pw and apitoken to ui
1 parent 88d2880 commit b9b43be

File tree

1 file changed

+2
-2
lines changed

1 file changed

+2
-2
lines changed

src/main/java/de/rwth/idsg/steve/service/WebUserService.java

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -195,8 +195,8 @@ public WebUserForm getDetails(Integer webUserPk) {
195195

196196
form.setEnabled(ur.getEnabled());
197197
form.setWebUsername(ur.getUsername());
198-
form.setPassword(ur.getPassword());
199-
form.setApiToken(ur.getApiToken());
198+
form.setPassword(""); // don't expose the pw
199+
form.setApiToken(""); // ur.getApiToken()
200200
form.setAuthorities(rolesStr(fromJson(ur.getAuthorities())));
201201

202202
return form;

0 commit comments

Comments
 (0)