Skip to content

Commit eae5cb1

Browse files
committed
Making it so all email requests return 200 as to obfuscate existing and non-existing users
1 parent df73a5a commit eae5cb1

File tree

1 file changed

+3
-2
lines changed

1 file changed

+3
-2
lines changed

src/routes/user.js

Lines changed: 3 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -49,9 +49,10 @@ router.post('/forgotpassword/:email', async(req, res) => {
4949
await email.sendForgotPassword(user.email, temporaryToken);
5050

5151
code = 200;
52-
message = `Password reset email sent successfully for ${user.email}`;
52+
message = `Password reset email sent`;
5353
} else {
54-
code = 404;
54+
code = 200;
55+
message = `Password reset email sent`;
5556
}
5657
} else {
5758
code = 422;

0 commit comments

Comments
 (0)