Skip to content

Commit 507be36

Browse files
Limit fields which can be updated in OpenController userSetupSave() function
1 parent 8e3c87a commit 507be36

File tree

1 file changed

+9
-8
lines changed

1 file changed

+9
-8
lines changed

app/Http/Controllers/OpenController.php

Lines changed: 9 additions & 8 deletions
Original file line numberDiff line numberDiff line change
@@ -87,14 +87,15 @@ public function userSetupSave($hash, Request $request)
8787
->withInput();
8888
}
8989

90-
$request_data = $request->all();
91-
// Do not allow user to set his role
92-
if (isset($request_data['role'])) {
93-
unset($request_data['role']);
94-
}
95-
if (isset($request_data['photo_url'])) {
96-
unset($request_data['photo_url']);
97-
}
90+
$request_data = [
91+
'email' => $request->email,
92+
'password' => $request->password,
93+
'job_title' => $request->job_title,
94+
'phone' => $request->phone,
95+
'timezone' => $request->timezone,
96+
'time_format' => $request->time_format,
97+
];
98+
9899
$user->fill($request_data);
99100

100101
$user->password = bcrypt($request->password);

0 commit comments

Comments
 (0)