From 5992f74e79014778a0101a11b32c8076a8b2a190 Mon Sep 17 00:00:00 2001 From: Swrup Date: Mon, 7 Feb 2022 21:09:39 +0100 Subject: [PATCH] fix user's data leak --- src/user.ml | 6 +++--- 1 file changed, 3 insertions(+), 3 deletions(-) diff --git a/src/user.ml b/src/user.ml index 06f6330..cb4f496 100644 --- a/src/user.ml +++ b/src/user.ml @@ -126,12 +126,12 @@ let list () = let public_profile request = let nick = Dream.param "user" request in - let^? nick, password, email, (bio, _) = Db.find_opt Q.get_user nick in + let^? nick, _password, _email, (bio, _) = Db.find_opt Q.get_user nick in let user_info = Format.sprintf - {|nick = `%s`; password = `%s`; email = `%s`; bio = '%s'; + {|nick = `%s`; bio = '%s'; Your avatar picture|} - nick password email (Dream.html_escape bio) nick + nick (Dream.html_escape bio) nick in Ok user_info