From ff1cb9036ed49d6782776936ec93d2f4ea04c455 Mon Sep 17 00:00:00 2001 From: Elliott Stoneham Date: Fri, 8 Jul 2016 15:29:01 +0100 Subject: [PATCH] Don't return actual token to JS for trello --- app/app/components/section/trello/type-editor.js | 2 +- documize/section/trello/trello.go | 4 +++- 2 files changed, 4 insertions(+), 2 deletions(-) diff --git a/app/app/components/section/trello/type-editor.js b/app/app/components/section/trello/type-editor.js index 9030b958..9392f020 100644 --- a/app/app/components/section/trello/type-editor.js +++ b/app/app/components/section/trello/type-editor.js @@ -59,7 +59,7 @@ export default Ember.Component.extend(SectionMixin, NotifierMixin, TooltipMixin, this.get('sectionService').fetch(page, "config", {}) .then(function (s) { self.set('appKey', s.appKey); - self.set('config.token', s.token); // the user's own token, drawn from the DB + self.set('config.token', s.token); // the user's own token has been stored in the DB // On auth callback capture user token let hashToken = window.location.hash; diff --git a/documize/section/trello/trello.go b/documize/section/trello/trello.go index 59327705..a28d5756 100644 --- a/documize/section/trello/trello.go +++ b/documize/section/trello/trello.go @@ -127,7 +127,9 @@ func (*Provider) Command(ctx *provider.Context, w http.ResponseWriter, r *http.R Token string `json:"token"` } ret.AppKey = config.AppKey - ret.Token = config.Token + if config.Token != "" { + ret.Token = provider.SecretReplacement + } provider.WriteJSON(w, ret) return