Skip to content

Commit 53c1246

Browse files
committed
whitelist fields
1 parent 37071c7 commit 53c1246

File tree

1 file changed

+3
-1
lines changed

1 file changed

+3
-1
lines changed

server/routes/surveyRoutes.js

+3-1
Original file line numberDiff line numberDiff line change
@@ -11,7 +11,9 @@ const Survey = mongoose.model('surveys');
1111

1212
module.exports = app => {
1313
app.get('/api/surveys', requireLogin, async (req, res) => {
14-
const surveys = await Survey.find({ _user: req.user.id });
14+
const surveys = await Survey.find({ _user: req.user.id }).select({
15+
recipients: false
16+
});
1517

1618
res.send(surveys);
1719
});

0 commit comments

Comments
 (0)