fix(09): WR-11 reject ambiguous admin logins and cross-field login or email collisions
This commit is contained in:
@@ -381,17 +381,22 @@ func adminBlacklist(app *backpack.App) bouncer.BlacklistStore {
|
||||
return bouncer.NewPostgresBlacklist(sqlDB, backendJWTBlacklistTable)
|
||||
}
|
||||
|
||||
// findBackendLogin resolves a login identifier (a login or an email) to one
|
||||
// administrator. An identifier that matches two rows, such as one admin's login
|
||||
// equal to another's email, resolves to nobody: it is reported as not found, so
|
||||
// the caller answers it like any wrong credential instead of letting the lowest
|
||||
// id win and lock the other admin out.
|
||||
func findBackendLogin(db *gorm.DB, identifier string) (BackendUser, bool, error) {
|
||||
email := strings.ToLower(identifier)
|
||||
var user BackendUser
|
||||
err := db.Preload("Role").Where("login = ? OR lower(email) = ?", identifier, email).First(&user).Error
|
||||
if errors.Is(err, gorm.ErrRecordNotFound) {
|
||||
return BackendUser{}, false, nil
|
||||
}
|
||||
var users []BackendUser
|
||||
err := db.Preload("Role").Where("login = ? OR lower(email) = ?", identifier, email).Order("id").Limit(2).Find(&users).Error
|
||||
if err != nil {
|
||||
return BackendUser{}, false, err
|
||||
}
|
||||
return user, true, nil
|
||||
if len(users) != 1 {
|
||||
return BackendUser{}, false, nil
|
||||
}
|
||||
return users[0], true, nil
|
||||
}
|
||||
|
||||
func (s *service) db() (*gorm.DB, error) {
|
||||
|
||||
Reference in New Issue
Block a user