Browse Source
Add validation for invalid password on login for users required to change password
pull/25482/head
maliming
4 months ago
No known key found for this signature in database
GPG Key ID: A646B9CB645ECEA4
1 changed files with
17 additions and
0 deletions
-
modules/account/src/Volo.Abp.Account.Web.IdentityServer/Pages/Account/IdentityServerSupportedLoginModel.cs
|
|
@ -159,6 +159,23 @@ public class IdentityServerSupportedLoginModel : LoginModel |
|
|
|
|
|
|
|
|
if (result.IsNotAllowed) |
|
|
if (result.IsNotAllowed) |
|
|
{ |
|
|
{ |
|
|
|
|
|
var notAllowedUser = await UserManager.FindByNameAsync(LoginInput.UserNameOrEmailAddress) ?? |
|
|
|
|
|
await UserManager.FindByEmailAsync(LoginInput.UserNameOrEmailAddress); |
|
|
|
|
|
if (notAllowedUser != null) |
|
|
|
|
|
{ |
|
|
|
|
|
using (CurrentTenant.Change(notAllowedUser.TenantId)) |
|
|
|
|
|
{ |
|
|
|
|
|
await IdentityOptions.SetAsync(); |
|
|
|
|
|
if ((notAllowedUser.ShouldChangePasswordOnNextLogin || |
|
|
|
|
|
await UserManager.ShouldPeriodicallyChangePasswordAsync(notAllowedUser)) && |
|
|
|
|
|
!await UserManager.CheckPasswordAsync(notAllowedUser, LoginInput.Password)) |
|
|
|
|
|
{ |
|
|
|
|
|
Alerts.Danger(L["InvalidUserNameOrPassword"]); |
|
|
|
|
|
return Page(); |
|
|
|
|
|
} |
|
|
|
|
|
} |
|
|
|
|
|
} |
|
|
|
|
|
|
|
|
Alerts.Warning(L["LoginIsNotAllowed"]); |
|
|
Alerts.Warning(L["LoginIsNotAllowed"]); |
|
|
return Page(); |
|
|
return Page(); |
|
|
} |
|
|
} |
|
|
|