Checking if user is blocked before session creation

This commit is contained in:
Eldad Fux
2020-12-27 13:57:42 +02:00
parent 8ff16c3fb8
commit 54f753f2a7
+12
View File
@@ -179,6 +179,10 @@ App::post('/v1/account/sessions')
throw new Exception('Invalid credentials', 401); // Wrong password or username
}
if (Auth::USER_STATUS_BLOCKED == $profile->getAttribute('status')) { // Account is blocked
throw new Exception('Invalid credentials. User is blocked', 401); // User is in status blocked
}
$dd = new DeviceDetector($request->getUserAgent('UNKNOWN'));
$dd->parse();
@@ -524,6 +528,10 @@ App::get('/v1/account/sessions/oauth2/:provider/redirect')
}
}
if (Auth::USER_STATUS_BLOCKED == $user->getAttribute('status')) { // Account is blocked
throw new Exception('Invalid credentials. User is blocked', 401); // User is in status blocked
}
// Create session token, verify user account and update OAuth2 ID and Access Token
$dd = new DeviceDetector($request->getUserAgent('UNKNOWN'));
@@ -1263,6 +1271,10 @@ App::post('/v1/account/recovery')
throw new Exception('User not found', 404); // TODO maybe hide this
}
if (Auth::USER_STATUS_BLOCKED == $profile->getAttribute('status')) { // Account is blocked
throw new Exception('Invalid credentials. User is blocked', 401); // User is in status blocked
}
$secret = Auth::tokenGenerator();
$recovery = new Document([
'$collection' => Database::SYSTEM_COLLECTION_TOKENS,