mirror of
https://github.com/casdoor/casdoor.git
synced 2025-09-08 12:11:03 +08:00
Remove password in JWT token payload.
This commit is contained in:
@@ -31,6 +31,8 @@ func generateJwtToken(application *Application, user *User) (string, error) {
|
|||||||
nowTime := time.Now()
|
nowTime := time.Now()
|
||||||
expireTime := nowTime.Add(time.Duration(application.ExpireInHours) * time.Hour)
|
expireTime := nowTime.Add(time.Duration(application.ExpireInHours) * time.Hour)
|
||||||
|
|
||||||
|
user.Password = ""
|
||||||
|
|
||||||
claims := Claims{
|
claims := Claims{
|
||||||
User: *user,
|
User: *user,
|
||||||
StandardClaims: jwt.StandardClaims{
|
StandardClaims: jwt.StandardClaims{
|
||||||
|
Reference in New Issue
Block a user