Fixing information disclosure when resetting password
parent
9c1c582577
commit
c2563125e5
|
@ -100,8 +100,7 @@ class UsersViewSet(ModelCrudViewSet):
|
||||||
email = mbuilder.password_recovery(user.email, {"user": user})
|
email = mbuilder.password_recovery(user.email, {"user": user})
|
||||||
email.send()
|
email.send()
|
||||||
|
|
||||||
return response.Ok({"detail": _("Mail sended successful!"),
|
return response.Ok({"detail": _("Mail sended successful!")})
|
||||||
"email": user.email})
|
|
||||||
|
|
||||||
@list_route(methods=["POST"])
|
@list_route(methods=["POST"])
|
||||||
def change_password_from_recovery(self, request, pk=None):
|
def change_password_from_recovery(self, request, pk=None):
|
||||||
|
|
Loading…
Reference in New Issue