invalid login credentials fixes

This commit is contained in:
Victor Piousbox
2016-03-21 21:10:17 +00:00
parent 5f5fc754b0
commit ddbb8a1beb
3 changed files with 13 additions and 15 deletions
+1
View File
@@ -12,6 +12,7 @@
"usernameTaken": "Username already taken.",
"passwordConfirmationMatch": "Password confirmation doesn't match password.",
"invalidLoginCredentials": "Incorrect username / email and / or password.",
"invalidLoginCredentialsLong": "Uh-oh - your username or password is incorrect.\n- Make sure your username or email is typed correctly.\n- You may have signed up with Facebook, not email. Double-check by trying Facebook login.\n- If you forgot your password, click \"Forgot Password\".",
"invalidCredentials": "User not found with given auth credentials.",
"accountSuspended": "Account has been suspended, please contact leslie@habitica.com with your UUID \"<%= userId %>\" for assistance.",
"onlyFbSupported": "Only Facebook supported currently.",
@@ -29,41 +29,41 @@ describe('POST /user/auth/local/login', () => {
});
it('user is blocked', async () => {
await user.update({ 'auth.blocked': 1 });
expect(api.post(endpoint, {
await expect(api.post(endpoint, {
username: user.auth.local.username,
password,
})).to.eventually.be.rejected.and.eql({
code: 400,
code: 401,
error: 'NotAuthorized',
message: t('accountSuspended', { userId: user._id }),
});
});
it('wrong password', async () => {
expect(api.post(endpoint, {
await expect(api.post(endpoint, {
username: user.auth.local.username,
password: 'wrong-password',
})).to.eventually.be.rejected.and.eql({
code: 400,
code: 401,
error: 'NotAuthorized',
message: t('wrongPassword'),
message: t('invalidLoginCredentialsLong'),
});
});
it('missing username', async () => {
expect(api.post(endpoint, {
await expect(api.post(endpoint, {
password: 'wrong-password',
})).to.eventually.be.rejected.and.eql({
code: 400,
error: 'NotAuthorized',
message: t('missingUsername'),
error: 'BadRequest',
message: t('invalidReqParams'),
});
});
it('missing password', async () => {
expect(api.post(endpoint, {
await expect(api.post(endpoint, {
username: user.auth.local.username,
})).to.eventually.be.rejected.and.eql({
code: 400,
error: 'NotAuthorized',
message: t('missingPassword'),
error: 'BadRequest',
message: t('invalidReqParams'),
});
});
});
+1 -4
View File
@@ -207,11 +207,8 @@ api.loginLocal = {
}
let user = await User.findOne(login, {auth: 1, apiToken: 1}).exec();
// TODO place back long error message return res.json(401, {err:"Uh-oh - your username or password is incorrect.\n- Make sure your username or email is typed correctly.\n- You may have signed up with Facebook, not email. Double-check by trying Facebook login.\n- If you forgot your password, click \"Forgot Password\"."});
let isValidPassword = user && user.auth.local.hashed_password === passwordUtils.encrypt(req.body.password, user.auth.local.salt);
if (!isValidPassword) throw new NotAuthorized(res.t('invalidLoginCredentials'));
if (!isValidPassword) throw new NotAuthorized(res.t('invalidLoginCredentialsLong'));
_loginRes(user, ...arguments);
},
};