raffinement refus de connexion

This commit is contained in:
Jean-Marie Place 2021-10-20 06:11:05 +02:00
parent e13172f414
commit 89f562a2e7

View File

@ -21,7 +21,7 @@ from app.auth.forms import (
) )
from app.auth.models import Permission from app.auth.models import Permission
from app.auth.models import User from app.auth.models import User
from app.auth.email import send_password_reset_email from app.auth.email import send_password_reset_email, is_disabled_email_addr
from app.decorators import admin_required from app.decorators import admin_required
from app.decorators import permission_required from app.decorators import permission_required
@ -37,6 +37,11 @@ def login():
if form.validate_on_submit(): if form.validate_on_submit():
user = User.query.filter_by(user_name=form.user_name.data).first() user = User.query.filter_by(user_name=form.user_name.data).first()
if user is None or not user.check_password(form.password.data): if user is None or not user.check_password(form.password.data):
if user and is_disabled_email_addr(user.email):
current_app.logger.info("login: compte invalidé (email doublonné) (%s)", form.user_name.data)
flash(_("compte invalidé pour conflit d'adresse email"))
return redirect(url_for("auth.login"))
else:
current_app.logger.info("login: invalid (%s)", form.user_name.data) current_app.logger.info("login: invalid (%s)", form.user_name.data)
flash(_("Nom ou mot de passe invalide")) flash(_("Nom ou mot de passe invalide"))
return redirect(url_for("auth.login")) return redirect(url_for("auth.login"))