Skip to content

Conversation

@ihsaan-ullah
Copy link
Collaborator

@ihsaan-ullah ihsaan-ullah commented Aug 2, 2023

@ mention of reviewers

@Didayolo @dtuantran

A brief description of the purpose of the changes contained in this PR.

Now inactive users will not be able to login with their email and password without account verification.

Issues this PR resolves

Checklist

  • Code review by me
  • Hand tested by me
  • I'm proud of my work
  • Code review by reviewer
  • Hand tested by reviewer
  • CircleCi tests are passing
  • Ready to merge

@ihsaan-ullah ihsaan-ullah changed the title Login - Do not allow inactive user to login Login - Do not allow inactive user to login with email Aug 2, 2023
@ihsaan-ullah ihsaan-ullah requested a review from dtuantran August 3, 2023 14:44
@Didayolo
Copy link
Member

Didayolo commented Aug 9, 2023

@ihsaan-ullah I haven't tested, but just by looking at the code I'm wondering:

Do we have a clear error/warning message in the case an user tries to connect using email but the account is incative?

@ihsaan-ullah
Copy link
Collaborator Author

@ihsaan-ullah I haven't tested, but just by looking at the code I'm wondering:

Do we have a clear error/warning message in the case an user tries to connect using email but the account is incative?

No, we just show this error : Wrong Credentials in all cases. We can improve it in another PR.
The reason for this PR was a security problem i.e. you were able to login through email without email verification.

@Didayolo Didayolo merged commit 209b19d into develop Aug 9, 2023
@Didayolo Didayolo deleted the user_login branch August 9, 2023 11:00
@Didayolo Didayolo mentioned this pull request Aug 9, 2023
9 tasks
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants