fix: user enumaration on forgot password page

This commit is contained in:
Elias Schneider
2024-02-18 21:46:50 +01:00
parent 6058dca273
commit 64515d77cf
23 changed files with 3323 additions and 1685 deletions

View File

@@ -34,7 +34,7 @@ export async function middleware(request: NextRequest) {
try {
const claims = jwtDecode<{ exp: number; isAdmin: boolean }>(
accessToken as string
accessToken as string,
);
if (claims.exp * 1000 > Date.now()) {
user = claims;