@ -9,6 +9,7 @@ const { createASession } = require("../../security/sessions")
const { getTenantId } = require ( "../../tenancy" )
const { getTenantId } = require ( "../../tenancy" )
const INVALID_ERR = "Invalid Credentials"
const INVALID_ERR = "Invalid Credentials"
const SSO_NO_PASSWORD = "SSO user does not have a password set"
exports . options = {
exports . options = {
passReqToCallback : true ,
passReqToCallback : true ,
@ -36,6 +37,19 @@ exports.authenticate = async function (ctx, email, password, done) {
return authError ( done , INVALID_ERR )
return authError ( done , INVALID_ERR )
}
}
// check that the user has a stored password before proceeding
if ( ! dbUser . password ) {
if (
( dbUser . account && dbUser . account . authType === "sso" ) || // root account sso
dbUser . thirdPartyProfile // internal sso
) {
return authError ( done , SSO_NO_PASSWORD )
}
console . error ( "User has no password" , dbUser )
return authError ( done , INVALID_ERR )
}
// authenticate
// authenticate
if ( await compare ( password , dbUser . password ) ) {
if ( await compare ( password , dbUser . password ) ) {
const sessionId = newid ( )
const sessionId = newid ( )