diff --git a/app/controllers/api/account.php b/app/controllers/api/account.php index 79e5a0be52..fd06fc0eaf 100644 --- a/app/controllers/api/account.php +++ b/app/controllers/api/account.php @@ -179,6 +179,10 @@ App::post('/v1/account/sessions') throw new Exception('Invalid credentials', 401); // Wrong password or username } + if (Auth::USER_STATUS_BLOCKED == $profile->getAttribute('status')) { // Account is blocked + throw new Exception('Invalid credentials. User is blocked', 401); // User is in status blocked + } + $dd = new DeviceDetector($request->getUserAgent('UNKNOWN')); $dd->parse(); @@ -524,6 +528,10 @@ App::get('/v1/account/sessions/oauth2/:provider/redirect') } } + if (Auth::USER_STATUS_BLOCKED == $user->getAttribute('status')) { // Account is blocked + throw new Exception('Invalid credentials. User is blocked', 401); // User is in status blocked + } + // Create session token, verify user account and update OAuth2 ID and Access Token $dd = new DeviceDetector($request->getUserAgent('UNKNOWN')); @@ -1263,6 +1271,10 @@ App::post('/v1/account/recovery') throw new Exception('User not found', 404); // TODO maybe hide this } + if (Auth::USER_STATUS_BLOCKED == $profile->getAttribute('status')) { // Account is blocked + throw new Exception('Invalid credentials. User is blocked', 401); // User is in status blocked + } + $secret = Auth::tokenGenerator(); $recovery = new Document([ '$collection' => Database::SYSTEM_COLLECTION_TOKENS,