🐛 fix(login.py): handle exceptions in login_to_get_access_token function to provide more detailed error messages

🐛 fix(users.py): only hash password if user is a superuser to prevent regular users from changing their password
This commit is contained in:
Gabriel Luiz Freitas Almeida 2023-09-25 19:34:17 -03:00
commit 1e0f81c135
2 changed files with 21 additions and 11 deletions

View file

@ -23,14 +23,22 @@ async def login_to_get_access_token(
db: Session = Depends(get_session),
# _: Session = Depends(get_current_active_user)
):
if user := authenticate_user(form_data.username, form_data.password, db):
return create_user_tokens(user_id=user.id, db=db, update_last_login=True)
else:
try:
user = authenticate_user(form_data.username, form_data.password, db)
if user:
return create_user_tokens(user_id=user.id, db=db, update_last_login=True)
else:
raise HTTPException(
status_code=status.HTTP_401_UNAUTHORIZED,
detail="Incorrect username or password",
headers={"WWW-Authenticate": "Bearer"},
)
except Exception as exc:
raise HTTPException(
status_code=status.HTTP_401_UNAUTHORIZED,
detail="Incorrect username or password",
headers={"WWW-Authenticate": "Bearer"},
)
status_code=status.HTTP_500_INTERNAL_SERVER_ERROR,
detail=str(exc),
) from exc
@router.get("/auto_login")

View file

@ -99,10 +99,12 @@ def patch_user(
raise HTTPException(
status_code=403, detail="You don't have the permission to update this user"
)
if user_update.password and not user.is_superuser:
raise HTTPException(
status_code=400, detail="You can't change your password here"
)
if user_update.password:
if not user.is_superuser:
raise HTTPException(
status_code=400, detail="You can't change your password here"
)
user_update.password = get_password_hash(user_update.password)
if user_db := get_user_by_id(session, user_id):
return update_user(user_db, user_update, session)