过滤请求中意外返回用户密码哈希的Strapi技术求助
问题解决:Strapi查询关联用户时过滤敏感字段
环境信息
- Strapi版本: 4.4.5
- 操作系统: linux
- 数据库: sqlite
- Node版本: 16.17.0
- Yarn版本: 1.22.19
问题说明
重载api::channel.channel控制器的find方法,目标是获取Channel表的product_id及关联用户的ID,但返回结果包含完整用户信息(含密码哈希值)。尝试在populate中用select指定仅返回ID,未生效。
可行解决方案
方案1:手动过滤返回数据(推荐)
在 sanitize 数据后,手动遍历结果,仅保留用户的id字段,这种方式精准可控,不会影响其他接口的字段返回逻辑。
修改后的控制器代码:
module.exports = createCoreController("api::channel.channel", ({ strapi }) => ({ async find(ctx) { const { user } = ctx.state; const entity = await strapi.service("api::channel.channel").find({ filters: { users: { id: { $in: user.id, }, }, }, populate: ["users"] }); const sanitizedEntity = await this.sanitizeOutput(entity, ctx); // 过滤用户字段,仅保留id if (sanitizedEntity.data) { sanitizedEntity.data.forEach(channel => { if (channel.attributes.users) { channel.attributes.users = channel.attributes.users.map(user => ({ id: user.id, attributes: { id: user.attributes.id } })); } }); } return this.transformResponse(sanitizedEntity); }, }));
方案2:通过内容类型权限全局限制
进入Strapi后台,找到**用户内容类型(User)**的权限设置,针对当前接口的访问角色,仅勾选id字段的访问权限。这种方式全局生效,适合所有需要限制用户字段的场景,但会影响其他依赖用户字段的接口。
方案3:调整Service查询的Populate语法
Strapi 4.x部分小版本中,嵌套字段选择需使用fields而非select,尝试修改populate配置:
populate: { users: { fields: ["id"] } }
内容的提问来源于stack exchange,提问作者Johanna Jato
相关产品推荐
相关产品推荐

