Skip to content
Extraits de code Groupes Projets
Valider db3ed498 rédigé par Eugen Rochko's avatar Eugen Rochko Validation de GitHub
Parcourir les fichiers

When OAuth password verification fails, return 401 instead of redirect (#5111)

Call to warden.authenticate! in resource_owner_from_credentials would
make the request redirect to sign-in path, which is a bad response for
apps. Now bad credentials just return nil, which leads to HTTP 401
from Doorkeeper. Also, accounts with enabled 2FA cannot be logged into
this way.
parent 901fc48a
Aucune branche associée trouvée
Aucune étiquette associée trouvée
Aucune requête de fusion associée trouvée
...@@ -7,15 +7,14 @@ Doorkeeper.configure do ...@@ -7,15 +7,14 @@ Doorkeeper.configure do
current_user || redirect_to(new_user_session_url) current_user || redirect_to(new_user_session_url)
end end
resource_owner_from_credentials do |routes| resource_owner_from_credentials do |_routes|
request.params[:user] = { email: request.params[:username], password: request.params[:password] } user = User.find_by(email: request.params[:username])
request.env["devise.allow_params_authentication"] = true user if !user&.otp_required_for_login? && user&.valid_password?(request.params[:password])
request.env["warden"].authenticate!(scope: :user)
end end
# If you want to restrict access to the web interface for adding oauth authorized applications, you need to declare the block below. # If you want to restrict access to the web interface for adding oauth authorized applications, you need to declare the block below.
admin_authenticator do admin_authenticator do
(current_user && current_user.admin?) || redirect_to(new_user_session_url) current_user&.admin? || redirect_to(new_user_session_url)
end end
# Authorization Code expiration time (default 10 minutes). # Authorization Code expiration time (default 10 minutes).
......
0% Chargement en cours ou .
You are about to add 0 people to the discussion. Proceed with caution.
Terminez d'abord l'édition de ce message.
Veuillez vous inscrire ou vous pour commenter