From 1e0f81c1354a5f40f58b620f6971c311494f5f0d Mon Sep 17 00:00:00 2001 From: Gabriel Luiz Freitas Almeida Date: Mon, 25 Sep 2023 19:34:17 -0300 Subject: [PATCH] =?UTF-8?q?=F0=9F=90=9B=20fix(login.py):=20handle=20except?= =?UTF-8?q?ions=20in=20login=5Fto=5Fget=5Faccess=5Ftoken=20function=20to?= =?UTF-8?q?=20provide=20more=20detailed=20error=20messages=20=F0=9F=90=9B?= =?UTF-8?q?=20fix(users.py):=20only=20hash=20password=20if=20user=20is=20a?= =?UTF-8?q?=20superuser=20to=20prevent=20regular=20users=20from=20changing?= =?UTF-8?q?=20their=20password?= MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit --- src/backend/langflow/api/v1/login.py | 22 +++++++++++++++------- src/backend/langflow/api/v1/users.py | 10 ++++++---- 2 files changed, 21 insertions(+), 11 deletions(-) diff --git a/src/backend/langflow/api/v1/login.py b/src/backend/langflow/api/v1/login.py index d45302c2e..e33eb8225 100644 --- a/src/backend/langflow/api/v1/login.py +++ b/src/backend/langflow/api/v1/login.py @@ -23,14 +23,22 @@ async def login_to_get_access_token( db: Session = Depends(get_session), # _: Session = Depends(get_current_active_user) ): - if user := authenticate_user(form_data.username, form_data.password, db): - return create_user_tokens(user_id=user.id, db=db, update_last_login=True) - else: + try: + user = authenticate_user(form_data.username, form_data.password, db) + + if user: + return create_user_tokens(user_id=user.id, db=db, update_last_login=True) + else: + raise HTTPException( + status_code=status.HTTP_401_UNAUTHORIZED, + detail="Incorrect username or password", + headers={"WWW-Authenticate": "Bearer"}, + ) + except Exception as exc: raise HTTPException( - status_code=status.HTTP_401_UNAUTHORIZED, - detail="Incorrect username or password", - headers={"WWW-Authenticate": "Bearer"}, - ) + status_code=status.HTTP_500_INTERNAL_SERVER_ERROR, + detail=str(exc), + ) from exc @router.get("/auto_login") diff --git a/src/backend/langflow/api/v1/users.py b/src/backend/langflow/api/v1/users.py index 19aaf81d5..73c7346d9 100644 --- a/src/backend/langflow/api/v1/users.py +++ b/src/backend/langflow/api/v1/users.py @@ -99,10 +99,12 @@ def patch_user( raise HTTPException( status_code=403, detail="You don't have the permission to update this user" ) - if user_update.password and not user.is_superuser: - raise HTTPException( - status_code=400, detail="You can't change your password here" - ) + if user_update.password: + if not user.is_superuser: + raise HTTPException( + status_code=400, detail="You can't change your password here" + ) + user_update.password = get_password_hash(user_update.password) if user_db := get_user_by_id(session, user_id): return update_user(user_db, user_update, session)