Skip to content
代码片段 群组 项目
提交 727dff3f 编辑于 作者: Timothy Andrew's avatar Timothy Andrew
浏览文件

Don't expose a user's private token in the `/api/v3/user` API.

- This would allow anyone with a personal access token (even a read-only
  token, once scopes are implemented) to escalate their access by
  obtaining the private token.
上级 4d042afe
No related branches found
No related tags found
加载中
加载中
0% 加载中 .
You are about to add 0 people to the discussion. Proceed with caution.
先完成此消息的编辑!
想要评论请 注册