diff --git a/test/api/unit/middlewares/errorHandler.test.js b/test/api/unit/middlewares/errorHandler.test.js index ba7c5998a5..2a755bad40 100644 --- a/test/api/unit/middlewares/errorHandler.test.js +++ b/test/api/unit/middlewares/errorHandler.test.js @@ -170,6 +170,7 @@ describe('errorHandler', () => { originalUrl: req.originalUrl, headers: req.headers, body: req.body, + query: req.query, httpCode: 400, isHandledError: true, }); diff --git a/website/server/controllers/api-v3/auth.js b/website/server/controllers/api-v3/auth.js index 3cafd1a1c0..c73384010f 100644 --- a/website/server/controllers/api-v3/auth.js +++ b/website/server/controllers/api-v3/auth.js @@ -160,8 +160,10 @@ api.redirectApple = { } let url = `/static/apple-redirect?code=${req.body.code}`; if (req.body.user) { - const { name } = JSON.parse(req.body.user); - url += `&name=${name.firstName} ${name.lastName}`; + const parsedBody = JSON.parse(req.body.user); + if (parsedBody && parsedBody.name) { + url += `&name=${parsedBody.name.firstName} ${parsedBody.name.lastName}`; + } } return res.redirect(303, url); }, diff --git a/website/server/middlewares/errorHandler.js b/website/server/middlewares/errorHandler.js index b73b9d6df3..79d2b42b27 100644 --- a/website/server/middlewares/errorHandler.js +++ b/website/server/middlewares/errorHandler.js @@ -69,6 +69,7 @@ export default function errorHandler (err, req, res, next) { // eslint-disable-l // don't send sensitive information that only adds noise headers: omit(req.headers, ['x-api-key', 'cookie', 'password', 'confirmPassword']), body: omit(req.body, ['password', 'confirmPassword']), + query: omit(req.query, ['password', 'confirmPassword']), httpCode: responseErr.httpCode, isHandledError: responseErr.httpCode < 500,