diff --git a/src/backend/langflow/api/v1/login.py b/src/backend/langflow/api/v1/login.py index d45302c2e..e33eb8225 100644 --- a/src/backend/langflow/api/v1/login.py +++ b/src/backend/langflow/api/v1/login.py @@ -23,14 +23,22 @@ async def login_to_get_access_token( db: Session = Depends(get_session), # _: Session = Depends(get_current_active_user) ): - if user := authenticate_user(form_data.username, form_data.password, db): - return create_user_tokens(user_id=user.id, db=db, update_last_login=True) - else: + try: + user = authenticate_user(form_data.username, form_data.password, db) + + if user: + return create_user_tokens(user_id=user.id, db=db, update_last_login=True) + else: + raise HTTPException( + status_code=status.HTTP_401_UNAUTHORIZED, + detail="Incorrect username or password", + headers={"WWW-Authenticate": "Bearer"}, + ) + except Exception as exc: raise HTTPException( - status_code=status.HTTP_401_UNAUTHORIZED, - detail="Incorrect username or password", - headers={"WWW-Authenticate": "Bearer"}, - ) + status_code=status.HTTP_500_INTERNAL_SERVER_ERROR, + detail=str(exc), + ) from exc @router.get("/auto_login") diff --git a/src/backend/langflow/api/v1/users.py b/src/backend/langflow/api/v1/users.py index 19aaf81d5..73c7346d9 100644 --- a/src/backend/langflow/api/v1/users.py +++ b/src/backend/langflow/api/v1/users.py @@ -99,10 +99,12 @@ def patch_user( raise HTTPException( status_code=403, detail="You don't have the permission to update this user" ) - if user_update.password and not user.is_superuser: - raise HTTPException( - status_code=400, detail="You can't change your password here" - ) + if user_update.password: + if not user.is_superuser: + raise HTTPException( + status_code=400, detail="You can't change your password here" + ) + user_update.password = get_password_hash(user_update.password) if user_db := get_user_by_id(session, user_id): return update_user(user_db, user_update, session)