fix: [security] disable email uniqueness validation for the self registration

pull/7459/head
iglocska 2021-05-28 10:37:01 +02:00
parent 72ccba98eb
commit c71f4c9f2a
No known key found for this signature in database
GPG Key ID: BEA224F1FEF113AC
1 changed files with 1 additions and 0 deletions

View File

@ -2450,6 +2450,7 @@ class UsersController extends AppController
throw new BadRequestException(__('We require at least the email field to be filled.'));
}
$this->User->set($requestObject);
unset($this->User->validate['email']['unique']);
if (!$this->User->validates(array('fieldList' => $fieldToValidate))) {
$errors = $this->User->validationErrors;
$message = __('Request could not be created.');