Browse Source

Add custom error codes for account lock and inactivity

pull/20716/head
maliming 1 year ago
parent
commit
aecc051fcb
No known key found for this signature in database GPG Key ID: A646B9CB645ECEA4
  1. 8
      modules/openiddict/src/Volo.Abp.OpenIddict.AspNetCore/Volo/Abp/OpenIddict/AbpOpenIddictErrors.cs
  2. 10
      modules/openiddict/src/Volo.Abp.OpenIddict.AspNetCore/Volo/Abp/OpenIddict/Controllers/TokenController.Password.cs

8
modules/openiddict/src/Volo.Abp.OpenIddict.AspNetCore/Volo/Abp/OpenIddict/AbpOpenIddictErrors.cs

@ -0,0 +1,8 @@
namespace Volo.Abp.OpenIddict;
public static class AbpOpenIddictErrors
{
public const string AccountLocked = "account_locked";
public const string AccountInactive = "account_inactive";
}

10
modules/openiddict/src/Volo.Abp.OpenIddict.AspNetCore/Volo/Abp/OpenIddict/Controllers/TokenController.Password.cs

@ -107,14 +107,14 @@ public partial class TokenController
ClientId = request.ClientId ClientId = request.ClientId
}); });
var errorCode = OpenIddictConstants.Errors.InvalidGrant;
string errorDescription; string errorDescription;
string errorCode;
if (result.IsLockedOut) if (result.IsLockedOut)
{ {
Logger.LogInformation("Authentication failed for username: {username}, reason: locked out", request.Username); Logger.LogInformation("Authentication failed for username: {username}, reason: locked out", request.Username);
errorCode = AbpOpenIddictErrors.AccountLocked;
errorDescription = "The user account has been locked out due to invalid login attempts. Please wait a while and try again."; errorDescription = "The user account has been locked out due to invalid login attempts. Please wait a while and try again.";
errorCode = "account_locked";
} }
else if (result.IsNotAllowed) else if (result.IsNotAllowed)
{ {
@ -127,7 +127,6 @@ public partial class TokenController
{ {
Logger.LogInformation("Authentication failed for username: {username}, reason: not allowed", request.Username); Logger.LogInformation("Authentication failed for username: {username}, reason: not allowed", request.Username);
if (user.ShouldChangePasswordOnNextLogin) if (user.ShouldChangePasswordOnNextLogin)
{ {
return await HandleShouldChangePasswordOnNextLoginAsync(request, user, request.Password); return await HandleShouldChangePasswordOnNextLoginAsync(request, user, request.Password);
@ -143,15 +142,14 @@ public partial class TokenController
return await HandleConfirmUserAsync(request, user); return await HandleConfirmUserAsync(request, user);
} }
errorCode = AbpOpenIddictErrors.AccountInactive;
errorDescription = "You are not allowed to login! Your account is inactive or needs to confirm your email/phone number."; errorDescription = "You are not allowed to login! Your account is inactive or needs to confirm your email/phone number.";
errorCode = "account_inactive";
} }
} }
else else
{ {
Logger.LogInformation("Authentication failed for username: {username}, reason: invalid credentials", request.Username); Logger.LogInformation("Authentication failed for username: {username}, reason: invalid credentials", request.Username);
errorDescription = "Invalid username or password!"; errorDescription = "Invalid username or password!";
errorCode = OpenIddictConstants.Errors.InvalidGrant;
} }
var properties = new AuthenticationProperties(new Dictionary<string, string> var properties = new AuthenticationProperties(new Dictionary<string, string>

Loading…
Cancel
Save