fix(secure): remove user list from roles and permissions field to avoid leaking userlist (#1614)

* fix(secure): remove user list from roles and permissions field to avoid leaking userlist

Signed-off-by: fengxsong <fengxsong@outlook.com>

* Update permission.go

* Update role.go

---------

Signed-off-by: fengxsong <fengxsong@outlook.com>
Co-authored-by: hsluoyz <hsluoyz@qq.com>
This commit is contained in:
fengxsong
2023-03-03 18:18:41 +08:00
committed by GitHub
parent 59c95ca8a0
commit 1ae6adff8e
2 changed files with 8 additions and 0 deletions

View File

@ -159,6 +159,10 @@ func GetRolesByUser(userId string) []*Role {
panic(err)
}
for i := range roles {
roles[i].Users = nil
}
return roles
}