From b67e4cecebe77cf687617fd487a64c3af823b6b7 Mon Sep 17 00:00:00 2001 From: Marcos Vinicius Spessatto Defendi Date: Thu, 19 Apr 2018 14:45:27 -0300 Subject: [PATCH] Remove "secret" from REST endpoint /settings.oauth response --- packages/rocketchat-api/server/v1/settings.js | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/packages/rocketchat-api/server/v1/settings.js b/packages/rocketchat-api/server/v1/settings.js index fc333c1994a..ac54adfd28e 100644 --- a/packages/rocketchat-api/server/v1/settings.js +++ b/packages/rocketchat-api/server/v1/settings.js @@ -32,7 +32,7 @@ RocketChat.API.v1.addRoute('settings.public', { authRequired: false }, { RocketChat.API.v1.addRoute('settings.oauth', { authRequired: false }, { get() { const mountOAuthServices = () => { - const oAuthServicesEnabled = ServiceConfiguration.configurations.find({}).fetch(); + const oAuthServicesEnabled = ServiceConfiguration.configurations.find({}, { fields: { secret: 0 } }).fetch(); return oAuthServicesEnabled.map((service) => { if (service.custom) {