Skip to content

Commit 95c1f38

Browse files
committed
fix: prevent mass-assignment of user field in createProject (#3876)
1 parent 97f761d commit 95c1f38

1 file changed

Lines changed: 1 addition & 5 deletions

File tree

server/controllers/project.controller/createProject.js

Lines changed: 1 addition & 5 deletions
Original file line numberDiff line numberDiff line change
@@ -6,11 +6,7 @@ import {
66
} from '../../domain-objects/Project';
77

88
export default function createProject(req, res) {
9-
let projectValues = {
10-
user: req.user._id
11-
};
12-
13-
projectValues = Object.assign(projectValues, req.body);
9+
const projectValues = Object.assign({}, req.body, { user: req.user._id });
1410

1511
function sendFailure(err) {
1612
res.status(400).json({ success: false });

0 commit comments

Comments
 (0)