fix: Correctly return M_USER_LOCKED during login

This commit is contained in:
timedout
2026-01-07 17:31:53 +00:00
parent 37574ef5cc
commit 88a35e139d
+5
View File
@@ -13,6 +13,7 @@ use futures::StreamExt;
use ruma::{ use ruma::{
OwnedUserId, UserId, OwnedUserId, UserId,
api::client::{ api::client::{
error::ErrorKind,
session::{ session::{
get_login_token, get_login_token,
get_login_types::{ get_login_types::{
@@ -185,6 +186,10 @@ pub(crate) async fn handle_login(
return Err!(Request(Unknown("User ID does not belong to this homeserver"))); return Err!(Request(Unknown("User ID does not belong to this homeserver")));
} }
if services.users.is_locked(&user_id)? {
return Err(Error::BadRequest(ErrorKind::UserLocked, "This account has been locked."));
}
if services.users.is_login_disabled(&user_id).await { if services.users.is_login_disabled(&user_id).await {
warn!(%user_id, "user attempted to log in with a login-disabled account"); warn!(%user_id, "user attempted to log in with a login-disabled account");
return Err!(Request(Forbidden("This account is not permitted to log in."))); return Err!(Request(Forbidden("This account is not permitted to log in.")));