The routes for user is not secure and needs to be fixed. Do this. While at it cleanup the update method in user.