Sfoglia il codice sorgente

Add early exit if account is deleted in login method

tags/v0.10.5
Kristijan Mitrovic 4 anni fa
parent
commit
39d49c1d94
1 ha cambiato i file con 1 aggiunte e 1 eliminazioni
  1. +1
    -1
      bubble-server/src/main/java/bubble/resources/account/AuthResource.java

+ 1
- 1
bubble-server/src/main/java/bubble/resources/account/AuthResource.java Vedi File

@@ -306,7 +306,7 @@ public class AuthResource {
if (!request.hasName()) return invalid("err.name.required", "name is required");
if (!request.hasPassword()) return invalid("err.password.required", "password is required");
final Account account = accountDAO.findByName(request.getName());
if (account == null) return notFound(request.getName());
if (account == null || account.deleted()) return notFound(request.getName());
if (!account.getHashedPassword().isCorrectPassword(request.getPassword())) {
return notFound(request.getName());
}


Caricamento…
Annulla
Salva