Merge pull request #203 from DerDackel/nopasswords
Remove password from log message upon login failure
This commit is contained in:
commit
fdc6b64f15
|
@ -105,7 +105,7 @@ func SignInPost(ctx *middleware.Context, form auth.LogInForm) {
|
||||||
user, err = models.LoginUser(form.UserName, form.Password)
|
user, err = models.LoginUser(form.UserName, form.Password)
|
||||||
if err != nil {
|
if err != nil {
|
||||||
if err == models.ErrUserNotExist {
|
if err == models.ErrUserNotExist {
|
||||||
log.Trace("%s Log in failed: %s/%s", ctx.Req.RequestURI, form.UserName, form.Password)
|
log.Trace("%s Log in failed: %s", ctx.Req.RequestURI, form.UserName)
|
||||||
ctx.RenderWithErr("Username or password is not correct", "user/signin", &form)
|
ctx.RenderWithErr("Username or password is not correct", "user/signin", &form)
|
||||||
return
|
return
|
||||||
}
|
}
|
||||||
|
|
Loading…
Reference in New Issue
Block a user