@@ -136,42 +136,6 @@ exports.get_account_details = function(req, res, next) {
136
136
return res . render ( 'account.hbs' , profile )
137
137
}
138
138
139
- // New NoSQL Injection vulnerability - added for Snyk testing
140
- /*
141
- exports.loginHandler = function (req, res, next) {
142
- if (validator.isEmail(req.body.username)) {
143
- User.find({ username: req.body.username, password: req.body.password }, function (err, users) {
144
- if (users.length > 0) {
145
- const redirectPage = req.body.redirectPage
146
- const session = req.session
147
- const username = req.body.username
148
- return adminLoginSuccess(redirectPage, session, username, res)
149
- } else {
150
- return res.status(401).send()
151
- }
152
- });
153
- } else {
154
- return res.status(401).send()
155
- }
156
- };
157
-
158
-
159
- if (validator.isEmail(req.body.username)) {
160
- User.find({ username: req.body.username, password: req.body.password }, function (err, users) {
161
- if (users.length > 0) {
162
- const redirectPage = req.body.redirectPage
163
- const session = req.session
164
- const username = req.body.username
165
- return adminLoginSuccess(redirectPage, session, username, res)
166
- } else {
167
- return res.status(401).send()
168
- }
169
- });
170
- } else {
171
- return res.status(401).send()
172
- };
173
- */
174
-
175
139
exports . save_account_details = function ( req , res , next ) {
176
140
// get the profile details from the JSON
177
141
const profile = req . body
@@ -302,7 +266,6 @@ exports.edit = function (req, res, next) {
302
266
});
303
267
});
304
268
};
305
- */
306
269
307
270
exports.update = function (req, res, next) {
308
271
Todo.findById(req.params.id, function (err, todo) {
@@ -316,7 +279,7 @@ exports.update = function (req, res, next) {
316
279
});
317
280
});
318
281
};
319
-
282
+ */
320
283
321
284
// ** express turns the cookie key to lowercase **
322
285
exports . current_user = function ( req , res , next ) {
0 commit comments