Do not deliver API key on settings API unless user has admin rights.
This commit is contained in:
parent
e9beffc799
commit
048ad78778
1 changed files with 1 additions and 1 deletions
|
|
@ -34,7 +34,7 @@ def getSettings():
|
|||
data = {
|
||||
"api": {
|
||||
"enabled": s.getBoolean(["api", "enabled"]),
|
||||
"key": s.get(["api", "key"]),
|
||||
"key": s.get(["api", "key"]) if admin_permission.can() else "n/a",
|
||||
"allowCrossOrigin": s.get(["api", "allowCrossOrigin"])
|
||||
},
|
||||
"appearance": {
|
||||
|
|
|
|||
Loading…
Reference in a new issue