瀏覽代碼

Add early exit if account is deleted in login method

tags/v0.10.5
Kristijan Mitrovic 4 年之前
父節點
當前提交
39d49c1d94
共有 1 個檔案被更改,包括 1 行新增1 行删除
  1. +1
    -1
      bubble-server/src/main/java/bubble/resources/account/AuthResource.java

+ 1
- 1
bubble-server/src/main/java/bubble/resources/account/AuthResource.java 查看文件

@@ -306,7 +306,7 @@ public class AuthResource {
if (!request.hasName()) return invalid("err.name.required", "name is required");
if (!request.hasPassword()) return invalid("err.password.required", "password is required");
final Account account = accountDAO.findByName(request.getName());
if (account == null) return notFound(request.getName());
if (account == null || account.deleted()) return notFound(request.getName());
if (!account.getHashedPassword().isCorrectPassword(request.getPassword())) {
return notFound(request.getName());
}


Loading…
取消
儲存