fullUser fixes

Set to null if user isn't logged in.

```delete fullUser.password;``` wasn't deleting the password so setting it to null instead.
pull/222/head
jameskopacz 2015-03-17 21:11:14 -05:00
parent a36f978856
commit 770d177873
1 changed files with 2 additions and 2 deletions

4
app.js
View File

@ -198,8 +198,8 @@ app.use(helmet.contentSecurityPolicy({
app.use(function (req, res, next) {
// Make user object available in templates.
fullUser = req.user;
delete fullUser.password;
fullUser = req.user ? req.user : null;
if (fullUser) fullUser.password = null;
res.locals.user = fullUser;
next();
});