Skip to content

Commit 2b3f003

Browse files
authored
verifyEmailChange : Validate user_id (#1058)
* Update EmailChangeController.php * Update EmailChangeController.php
1 parent eb5e4d4 commit 2b3f003

1 file changed

Lines changed: 6 additions & 0 deletions

File tree

app/Http/Controllers/EmailChangeController.php

Lines changed: 6 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -132,6 +132,12 @@ public function verifyEmailChange(Request $request)
132132
'user_id' => 'required|integer|min:1|max:9999999999',
133133
'token' => 'required|string',
134134
]);
135+
136+
$user = $request->user();
137+
if ($request->input('user_id') != $user->id) {
138+
return $this->error('Invalid user_id value, please try again', 422);
139+
}
140+
135141
$id = $request->input('user_id');
136142
$token = $request->input('token');
137143

0 commit comments

Comments
 (0)