From: Dessalines Date: Thu, 5 Mar 2020 20:46:33 +0000 (-0500) Subject: Remove email from GetUserDetails when not same user. Fixes #579 X-Git-Url: http://these/git/%7B%60%24%7BwebArchiveUrl%7D/%22%7B%7D/%24%7B%60data:application/%22https:/hacktivis.me/%7BmarkdownHelpUrl%7D?a=commitdiff_plain;h=876d3117062f3f801026d72c9359613eca7e46ed;p=lemmy.git Remove email from GetUserDetails when not same user. Fixes #579 --- diff --git a/server/src/api/user.rs b/server/src/api/user.rs index 99072a74..1d332b90 100644 --- a/server/src/api/user.rs +++ b/server/src/api/user.rs @@ -466,7 +466,7 @@ impl Perform for Oper { } }; - let user_view = UserView::read(&conn, user_details_id)?; + let mut user_view = UserView::read(&conn, user_details_id)?; let mut posts_query = PostQueryBuilder::create(&conn) .sort(&sort) @@ -502,6 +502,15 @@ impl Perform for Oper { let creator_user = admins.remove(creator_index); admins.insert(0, creator_user); + // If its not the same user, remove the email + if let Some(user_id) = user_id { + if user_details_id != user_id { + user_view.email = None; + } + } else { + user_view.email = None; + } + // Return the jwt Ok(GetUserDetailsResponse { user: user_view,