diff --git a/src/users.js b/src/users.js index 14dd2d371..ee2384e7a 100644 --- a/src/users.js +++ b/src/users.js @@ -133,7 +133,7 @@ function validatePassword(password) { // remove all fields that should never be sent out via REST API function removePrivateFields(user) { - return _.pick(user, 'id', 'username', 'email', 'fallbackEmail', 'displayName', 'groupIds', 'active', 'source', 'role'); + return _.pick(user, 'id', 'username', 'email', 'fallbackEmail', 'displayName', 'groupIds', 'active', 'source', 'role', 'createdAt', 'twoFactorAuthenticationEnabled'); } // remove all fields that Non-privileged users must not see