Only allow local login if password is non-empty (#5906)
This commit is contained in:
parent
80098bd752
commit
0f295ababa
2 changed files with 2 additions and 2 deletions
|
@ -582,7 +582,7 @@ func parseToken(authorization string) (*models.User, *models.Repository, string,
|
|||
if err != nil {
|
||||
return nil, nil, "basic", err
|
||||
}
|
||||
if !u.ValidatePassword(password) {
|
||||
if !u.IsPasswordSet() || !u.ValidatePassword(password) {
|
||||
return nil, nil, "basic", fmt.Errorf("Basic auth failed")
|
||||
}
|
||||
return u, nil, "basic", nil
|
||||
|
|
Loading…
Add table
Add a link
Reference in a new issue