mirror of
https://forgejo.ellis.link/continuwuation/continuwuity.git
synced 2026-05-26 20:49:55 +00:00
fix: Address review comments
This commit is contained in:
@@ -14,7 +14,7 @@ use ruma::{
|
|||||||
OwnedUserId, UserId,
|
OwnedUserId, UserId,
|
||||||
api::client::{
|
api::client::{
|
||||||
account::{
|
account::{
|
||||||
register::{self, LoginType},
|
register::{self, LoginType, RegistrationKind},
|
||||||
request_registration_token_via_email,
|
request_registration_token_via_email,
|
||||||
},
|
},
|
||||||
uiaa::{AuthFlow, AuthType},
|
uiaa::{AuthFlow, AuthType},
|
||||||
@@ -48,6 +48,10 @@ pub(crate) async fn register_route(
|
|||||||
ClientIp(client): ClientIp,
|
ClientIp(client): ClientIp,
|
||||||
body: Ruma<register::v3::Request>,
|
body: Ruma<register::v3::Request>,
|
||||||
) -> Result<register::v3::Response> {
|
) -> Result<register::v3::Response> {
|
||||||
|
if body.kind != RegistrationKind::User {
|
||||||
|
return Err!(Request(GuestAccessForbidden("Guests may not register on this server.")));
|
||||||
|
}
|
||||||
|
|
||||||
let emergency_mode_enabled = services.config.emergency_password.is_some();
|
let emergency_mode_enabled = services.config.emergency_password.is_some();
|
||||||
|
|
||||||
// Allow registration if it's enabled in the config file or if this is the first
|
// Allow registration if it's enabled in the config file or if this is the first
|
||||||
|
|||||||
+18
-13
@@ -369,20 +369,25 @@ impl Service {
|
|||||||
|
|
||||||
/// Check a user's password.
|
/// Check a user's password.
|
||||||
pub async fn check_password(&self, user_id: &UserId, password: &str) -> Result<OwnedUserId> {
|
pub async fn check_password(&self, user_id: &UserId, password: &str) -> Result<OwnedUserId> {
|
||||||
let (hash, user_id): (String, OwnedUserId) =
|
let (hash, user_id): (String, OwnedUserId) = if let Ok(hash) =
|
||||||
if let Ok(hash) = self.db.userid_password.get(user_id).await.deserialized() {
|
self.db.userid_password.get(user_id).await.deserialized()
|
||||||
(hash, user_id.to_owned())
|
{
|
||||||
} else {
|
(hash, user_id.to_owned())
|
||||||
// We also check the lowercased version of the user ID to handle legacy user IDs
|
} else {
|
||||||
// better
|
// We also check the lowercased version of the user ID to handle legacy user IDs
|
||||||
let lowercase_user_id = UserId::parse(user_id.as_str().to_lowercase()).unwrap();
|
// better
|
||||||
|
let lowercase_user_id = UserId::parse(user_id.as_str().to_lowercase()).unwrap();
|
||||||
|
|
||||||
if let Ok(hash) = self.db.userid_password.get(user_id).await.deserialized() {
|
if let Ok(hash) = self.db.userid_password.get(user_id).await.deserialized() {
|
||||||
(hash, lowercase_user_id)
|
(hash, lowercase_user_id)
|
||||||
} else {
|
} else {
|
||||||
return Err!(Request(UserDeactivated("This user is deactivated.")));
|
return Err!(Request(InvalidParam("This user cannot log in with a password.")));
|
||||||
}
|
}
|
||||||
};
|
};
|
||||||
|
|
||||||
|
if hash.is_empty() {
|
||||||
|
return Err!(Request(UserDeactivated("This user is deactivated")));
|
||||||
|
}
|
||||||
|
|
||||||
utils::hash::verify_password(password, &hash)
|
utils::hash::verify_password(password, &hash)
|
||||||
.inspect_err(|e| debug_error!("{e}"))
|
.inspect_err(|e| debug_error!("{e}"))
|
||||||
|
|||||||
Reference in New Issue
Block a user