mirror of
https://github.com/infiniflow/ragflow.git
synced 2026-08-12 11:43:39 +08:00
fix: prevent sensitive fields from leaking in user API responses (#14792)
Closes #14789 ### What problem does this PR solve? User API endpoints (`login`, `user_profile`, `user_add`, `forget_reset_password`) were returning full user objects via `to_json()` / `to_dict()`, which included sensitive fields like `password` and `access_token` in the response body. This leaks credentials to the client. This PR adds a `to_safe_dict()` method on the `User` model that strips sensitive fields (`password`, `access_token`) and replaces all affected call sites to use it. ### Type of change - [x] Bug Fix (non-breaking change which fixes an issue)
This commit is contained in:
@@ -705,6 +705,8 @@ def fill_db_model_object(model_object, human_model_dict):
|
||||
|
||||
|
||||
class User(DataBaseModel, AuthUser):
|
||||
SENSITIVE_FIELDS = {"password", "access_token", "email"}
|
||||
|
||||
id = CharField(max_length=32, primary_key=True)
|
||||
access_token = CharField(max_length=255, null=True, index=True)
|
||||
nickname = CharField(max_length=100, null=False, help_text="nicky name", index=True)
|
||||
@@ -729,6 +731,18 @@ class User(DataBaseModel, AuthUser):
|
||||
jwt = Serializer(secret_key=settings.get_secret_key())
|
||||
return jwt.dumps(str(self.access_token))
|
||||
|
||||
def to_safe_dict(self, *, for_self: bool = False):
|
||||
"""Return a dict with sensitive fields stripped for API responses.
|
||||
|
||||
Email is treated as sensitive in generic serialization. Pass for_self=True
|
||||
when returning the authenticated user's own record (login, profile, etc.).
|
||||
"""
|
||||
result = {k: v for k, v in self.to_dict().items() if k not in self.SENSITIVE_FIELDS}
|
||||
if for_self:
|
||||
result["email"] = self.email
|
||||
logging.debug("User %s serialized safely, filtered fields: %s", self.id, self.SENSITIVE_FIELDS)
|
||||
return result
|
||||
|
||||
class Meta:
|
||||
db_table = "user"
|
||||
|
||||
|
||||
Reference in New Issue
Block a user