Преглед на файлове

Handle one time password better

Signed-off-by: Carl Schwan <carl@carlschwan.eu>
Carl Schwan преди 2 години
родител
ревизия
702445ba3b
променени са 2 файла, в които са добавени 10 реда и са изтрити 2 реда
  1. 1 1
      lib/private/Authentication/Token/PublicKeyTokenProvider.php
  2. 9 1
      tests/lib/Authentication/Token/PublicKeyTokenProviderTest.php

+ 1 - 1
lib/private/Authentication/Token/PublicKeyTokenProvider.php

@@ -401,7 +401,7 @@ class PublicKeyTokenProvider implements IProvider {
 		$this->cache->clear();
 
 		// prevent setting an empty pw as result of pw-less-login
-		if ($password === '') {
+		if ($password === '' || !$this->config->getSystemValueBool('auth.storeCryptedPassword', true)) {
 			return;
 		}
 

+ 9 - 1
tests/lib/Authentication/Token/PublicKeyTokenProviderTest.php

@@ -98,7 +98,7 @@ class PublicKeyTokenProviderTest extends TestCase {
 		$this->assertSame($password, $this->tokenProvider->getPassword($actual, $token));
 	}
 
-	public function testGenerateTokenNoPassword() {
+	public function testGenerateTokenNoPassword(): void {
 		$token = 'token';
 		$uid = 'user';
 		$user = 'User';
@@ -171,6 +171,10 @@ class PublicKeyTokenProviderTest extends TestCase {
 			->method('updateActivity')
 			->with($tk, $this->time);
 		$tk->setLastActivity($this->time - 200);
+		$this->config->method('getSystemValueBool')
+			->willReturnMap([
+				['auth.storeCryptedPassword', true, true],
+			]);
 
 		$this->tokenProvider->updateTokenActivity($tk);
 
@@ -578,6 +582,10 @@ class PublicKeyTokenProviderTest extends TestCase {
 			'random2',
 			IToken::PERMANENT_TOKEN,
 			IToken::REMEMBER);
+		$this->config->method('getSystemValueBool')
+			->willReturnMap([
+				['auth.storeCryptedPassword', true, true],
+			]);
 
 		$this->mapper->method('hasExpiredTokens')
 			->with($uid)