Quellcode durchsuchen

Add early exit if account is deleted in login method

tags/v0.10.5
Kristijan Mitrovic vor 4 Jahren
Ursprung
Commit
39d49c1d94
1 geänderte Dateien mit 1 neuen und 1 gelöschten Zeilen
  1. +1
    -1
      bubble-server/src/main/java/bubble/resources/account/AuthResource.java

+ 1
- 1
bubble-server/src/main/java/bubble/resources/account/AuthResource.java Datei anzeigen

@@ -306,7 +306,7 @@ public class AuthResource {
if (!request.hasName()) return invalid("err.name.required", "name is required");
if (!request.hasPassword()) return invalid("err.password.required", "password is required");
final Account account = accountDAO.findByName(request.getName());
if (account == null) return notFound(request.getName());
if (account == null || account.deleted()) return notFound(request.getName());
if (!account.getHashedPassword().isCorrectPassword(request.getPassword())) {
return notFound(request.getName());
}


Laden…
Abbrechen
Speichern