Skip to content

Commit 03adefd

Browse files
nickvergessenbackportbot[bot]
authored andcommitted
fix: Handle 2fa enforcement earlier
Signed-off-by: Joas Schilling <coding@schilljs.com>
1 parent e883c95 commit 03adefd

1 file changed

Lines changed: 4 additions & 5 deletions

File tree

‎lib/private/User/Session.php‎

Lines changed: 4 additions & 5 deletions
Original file line numberDiff line numberDiff line change
@@ -403,10 +403,8 @@ public function logClientIn($user,
403403
return false;
404404
}
405405

406-
if (!$isTokenPassword && $this->isTokenAuthEnforced()) {
407-
throw new PasswordLoginForbiddenException();
408-
}
409-
if (!$isTokenPassword && $this->isTwoFactorEnforced($user)) {
406+
if (!$isTokenPassword && ($this->isTokenAuthEnforced() || $this->isTwoFactorEnforced($user))) {
407+
$this->handleLoginFailed($throttler, $currentDelay, $remoteAddress, $user, $password);
410408
throw new PasswordLoginForbiddenException();
411409
}
412410

@@ -587,7 +585,8 @@ public function tryBasicAuthLogin(IRequest $request,
587585
// If credentials were provided, they need to be valid, otherwise we do boom
588586
throw new LoginException();
589587
} catch (PasswordLoginForbiddenException $ex) {
590-
// Nothing to do
588+
// If credentials were provided, they need to be valid, otherwise we do boom
589+
throw new LoginException(previous: $ex);
591590
}
592591
}
593592
return false;

0 commit comments

Comments
 (0)