Display Lockout Error to User (#11135)
Этот коммит содержится в:
коммит произвёл
GitHub
родитель
03e5525fa6
Коммит
f49a0881bf
@@ -1240,7 +1240,7 @@ func sendPasswordReset(c *Context, w http.ResponseWriter, r *http.Request) {
|
|||||||
}
|
}
|
||||||
|
|
||||||
func login(c *Context, w http.ResponseWriter, r *http.Request) {
|
func login(c *Context, w http.ResponseWriter, r *http.Request) {
|
||||||
// Translate all login errors to generic. MFA error being an exception, since it's required for the login flow itself
|
// Mask all sensitive errors, with the exception of the following
|
||||||
defer func() {
|
defer func() {
|
||||||
if c.Err == nil {
|
if c.Err == nil {
|
||||||
return
|
return
|
||||||
@@ -1254,6 +1254,7 @@ func login(c *Context, w http.ResponseWriter, r *http.Request) {
|
|||||||
"api.user.login.client_side_cert.certificate.app_error",
|
"api.user.login.client_side_cert.certificate.app_error",
|
||||||
"api.user.login.inactive.app_error",
|
"api.user.login.inactive.app_error",
|
||||||
"api.user.login.not_verified.app_error",
|
"api.user.login.not_verified.app_error",
|
||||||
|
"api.user.check_user_login_attempts.too_many.app_error",
|
||||||
}
|
}
|
||||||
|
|
||||||
maskError := true
|
maskError := true
|
||||||
|
|||||||
@@ -4220,13 +4220,13 @@ func TestLoginLockout(t *testing.T) {
|
|||||||
_, resp = th.Client.Login(th.BasicUser.Email, "wrong")
|
_, resp = th.Client.Login(th.BasicUser.Email, "wrong")
|
||||||
CheckErrorMessage(t, resp, "api.user.login.invalid_credentials_email_username")
|
CheckErrorMessage(t, resp, "api.user.login.invalid_credentials_email_username")
|
||||||
_, resp = th.Client.Login(th.BasicUser.Email, "wrong")
|
_, resp = th.Client.Login(th.BasicUser.Email, "wrong")
|
||||||
CheckErrorMessage(t, resp, "api.user.login.invalid_credentials_email_username")
|
CheckErrorMessage(t, resp, "api.user.check_user_login_attempts.too_many.app_error")
|
||||||
_, resp = th.Client.Login(th.BasicUser.Email, "wrong")
|
_, resp = th.Client.Login(th.BasicUser.Email, "wrong")
|
||||||
CheckErrorMessage(t, resp, "api.user.login.invalid_credentials_email_username")
|
CheckErrorMessage(t, resp, "api.user.check_user_login_attempts.too_many.app_error")
|
||||||
|
|
||||||
//Check if lock is active
|
//Check if lock is active
|
||||||
_, resp = th.Client.Login(th.BasicUser.Email, th.BasicUser.Password)
|
_, resp = th.Client.Login(th.BasicUser.Email, th.BasicUser.Password)
|
||||||
CheckErrorMessage(t, resp, "api.user.login.invalid_credentials_email_username")
|
CheckErrorMessage(t, resp, "api.user.check_user_login_attempts.too_many.app_error")
|
||||||
|
|
||||||
// Fake user has MFA enabled
|
// Fake user has MFA enabled
|
||||||
if result := <-th.Server.Store.User().UpdateMfaActive(th.BasicUser2.Id, true); result.Err != nil {
|
if result := <-th.Server.Store.User().UpdateMfaActive(th.BasicUser2.Id, true); result.Err != nil {
|
||||||
@@ -4239,9 +4239,9 @@ func TestLoginLockout(t *testing.T) {
|
|||||||
_, resp = th.Client.LoginWithMFA(th.BasicUser2.Email, th.BasicUser2.Password, "000000")
|
_, resp = th.Client.LoginWithMFA(th.BasicUser2.Email, th.BasicUser2.Password, "000000")
|
||||||
CheckErrorMessage(t, resp, "api.user.check_user_mfa.bad_code.app_error")
|
CheckErrorMessage(t, resp, "api.user.check_user_mfa.bad_code.app_error")
|
||||||
_, resp = th.Client.LoginWithMFA(th.BasicUser2.Email, th.BasicUser2.Password, "000000")
|
_, resp = th.Client.LoginWithMFA(th.BasicUser2.Email, th.BasicUser2.Password, "000000")
|
||||||
CheckErrorMessage(t, resp, "api.user.login.invalid_credentials_email_username")
|
CheckErrorMessage(t, resp, "api.user.check_user_login_attempts.too_many.app_error")
|
||||||
_, resp = th.Client.LoginWithMFA(th.BasicUser2.Email, th.BasicUser2.Password, "000000")
|
_, resp = th.Client.LoginWithMFA(th.BasicUser2.Email, th.BasicUser2.Password, "000000")
|
||||||
CheckErrorMessage(t, resp, "api.user.login.invalid_credentials_email_username")
|
CheckErrorMessage(t, resp, "api.user.check_user_login_attempts.too_many.app_error")
|
||||||
|
|
||||||
// Fake user has MFA disabled
|
// Fake user has MFA disabled
|
||||||
if result := <-th.Server.Store.User().UpdateMfaActive(th.BasicUser2.Id, false); result.Err != nil {
|
if result := <-th.Server.Store.User().UpdateMfaActive(th.BasicUser2.Id, false); result.Err != nil {
|
||||||
@@ -4250,5 +4250,5 @@ func TestLoginLockout(t *testing.T) {
|
|||||||
|
|
||||||
//Check if lock is active
|
//Check if lock is active
|
||||||
_, resp = th.Client.Login(th.BasicUser2.Email, th.BasicUser2.Password)
|
_, resp = th.Client.Login(th.BasicUser2.Email, th.BasicUser2.Password)
|
||||||
CheckErrorMessage(t, resp, "api.user.login.invalid_credentials_email_username")
|
CheckErrorMessage(t, resp, "api.user.check_user_login_attempts.too_many.app_error")
|
||||||
}
|
}
|
||||||
|
|||||||
Ссылка в новой задаче
Block a user