mirror of
https://forgejo.ellis.link/continuwuation/continuwuity.git
synced 2026-05-26 20:49:55 +00:00
fix: Don't let logged-in users access the registration page
This commit is contained in:
@@ -13,7 +13,7 @@ use conduwuit_service::{
|
|||||||
use futures::StreamExt;
|
use futures::StreamExt;
|
||||||
use lettre::{Address, message::Mailbox};
|
use lettre::{Address, message::Mailbox};
|
||||||
use ruma::{ClientSecret, OwnedClientSecret, OwnedServerName, OwnedSessionId, OwnedUserId};
|
use ruma::{ClientSecret, OwnedClientSecret, OwnedServerName, OwnedSessionId, OwnedUserId};
|
||||||
use serde::{Deserialize, Serialize};
|
use serde::{Deserialize, Serialize, de::IgnoredAny};
|
||||||
use tower_sessions::Session;
|
use tower_sessions::Session;
|
||||||
use validator::{Validate, ValidationError, ValidationErrors};
|
use validator::{Validate, ValidationError, ValidationErrors};
|
||||||
|
|
||||||
@@ -127,6 +127,16 @@ async fn route_register(
|
|||||||
Expect(Query(query)): Expect<Query<RegistrationQuery>>,
|
Expect(Query(query)): Expect<Query<RegistrationQuery>>,
|
||||||
PostForm(form): PostForm<RegistrationForm>,
|
PostForm(form): PostForm<RegistrationForm>,
|
||||||
) -> Result {
|
) -> Result {
|
||||||
|
if session_store
|
||||||
|
.get::<IgnoredAny>(User::KEY)
|
||||||
|
.await
|
||||||
|
.unwrap()
|
||||||
|
.is_some()
|
||||||
|
{
|
||||||
|
// Redirect already logged-in users to the account panel
|
||||||
|
return response!(Redirect::to(&LoginTarget::Account.target_path()));
|
||||||
|
}
|
||||||
|
|
||||||
let validation_errors = if let Some(form) = form {
|
let validation_errors = if let Some(form) = form {
|
||||||
match form.validate() {
|
match form.validate() {
|
||||||
| Ok(()) => {
|
| Ok(()) => {
|
||||||
@@ -246,6 +256,14 @@ async fn get_register_email_validate(
|
|||||||
threepid: ThreepidQuery { client_secret, session_id },
|
threepid: ThreepidQuery { client_secret, session_id },
|
||||||
})): Expect<Query<RegisterEmailValidateQuery>>,
|
})): Expect<Query<RegisterEmailValidateQuery>>,
|
||||||
) -> Result {
|
) -> Result {
|
||||||
|
let Ok(session) = services
|
||||||
|
.threepid
|
||||||
|
.get_valid_session(&session_id, &client_secret)
|
||||||
|
.await
|
||||||
|
else {
|
||||||
|
return response!(RegisterEmailValidate::new(context, session_id, client_secret, true));
|
||||||
|
};
|
||||||
|
|
||||||
let Some(completed_registration) = session_store
|
let Some(completed_registration) = session_store
|
||||||
.get::<CompletedRegistration>(COMPLETED_REGISTRATION_KEY)
|
.get::<CompletedRegistration>(COMPLETED_REGISTRATION_KEY)
|
||||||
.await
|
.await
|
||||||
@@ -256,14 +274,6 @@ async fn get_register_email_validate(
|
|||||||
));
|
));
|
||||||
};
|
};
|
||||||
|
|
||||||
let Ok(session) = services
|
|
||||||
.threepid
|
|
||||||
.get_valid_session(&session_id, &client_secret)
|
|
||||||
.await
|
|
||||||
else {
|
|
||||||
return response!(RegisterEmailValidate::new(context, session_id, client_secret, true,));
|
|
||||||
};
|
|
||||||
|
|
||||||
let email = session.consume();
|
let email = session.consume();
|
||||||
|
|
||||||
complete_registration(&services, session_store, completed_registration, Some(email)).await;
|
complete_registration(&services, session_store, completed_registration, Some(email)).await;
|
||||||
|
|||||||
Reference in New Issue
Block a user