Browse Source

fix(user/update-email)

兩足大貓貓 5 years ago
parent
commit
43141132ad
1 changed files with 2 additions and 1 deletions
  1. 2 1
      src/Controllers/UserController.php

+ 2 - 1
src/Controllers/UserController.php

@@ -662,7 +662,8 @@ class UserController extends BaseController
             $res['msg'] = '新邮箱不能和旧邮箱一样';
             return $response->getBody()->write(json_encode($res));
         }
-        $user->email = $newemail;
+        $antiXss = new AntiXSS();
+        $user->email = $antiXss->xss_clean($newemail);
         $user->save();
 
         $res['ret'] = 1;