From fa2d87ef187fb6797832446562e85cef45c2605c Mon Sep 17 00:00:00 2001 From: Evert Prants Date: Wed, 23 Oct 2019 17:00:06 +0300 Subject: [PATCH] Don't include user UUID in public API endpoint --- app.js | 1 + 1 file changed, 1 insertion(+) diff --git a/app.js b/app.js index e0531b3..6efb719 100644 --- a/app.js +++ b/app.js @@ -451,6 +451,7 @@ app.get('/api/channel/:name', async (req, res) => { if (!data) return res.jsonp({ error: 'No such channel!' }) let links = await db.all('SELECT * FROM link WHERE uuid = ?', data.user_uuid) + delete data.user_uuid data.live = data.live_at != null data.live_at = new Date(parseInt(data.live_at)) data.last_stream = new Date(parseInt(data.last_stream))