fix: hide sensitive email change fields in team member responses

This commit is contained in:
Yihang Wang
2025-09-18 00:40:09 +08:00
parent 9d1369e7f8
commit 844a67a006

View File

@@ -179,6 +179,8 @@ class TeamController extends Controller
$members = $team->members; $members = $team->members;
$members->makeHidden([ $members->makeHidden([
'pivot', 'pivot',
'email_change_code',
'email_change_code_expires_at',
]); ]);
return response()->json( return response()->json(
@@ -264,6 +266,8 @@ class TeamController extends Controller
$team = auth()->user()->currentTeam(); $team = auth()->user()->currentTeam();
$team->members->makeHidden([ $team->members->makeHidden([
'pivot', 'pivot',
'email_change_code',
'email_change_code_expires_at',
]); ]);
return response()->json( return response()->json(