diff --git a/lib/cartodb/middleware/clean-up-query-params.js b/lib/cartodb/middleware/clean-up-query-params.js index 2553380d..d5c93c07 100644 --- a/lib/cartodb/middleware/clean-up-query-params.js +++ b/lib/cartodb/middleware/clean-up-query-params.js @@ -20,11 +20,7 @@ module.exports = function cleanUpQueryParamsMiddleware (customQueryParams = []) } return function cleanUpQueryParams (req, res, next) { - var allowedQueryParams = REQUEST_QUERY_PARAMS_WHITELIST; - - if (Array.isArray(customQueryParams)) { - allowedQueryParams = allowedQueryParams.concat(customQueryParams); - } + const allowedQueryParams = [...REQUEST_QUERY_PARAMS_WHITELIST, ...customQueryParams]; req.query = _.pick(req.query, allowedQueryParams);