🐛 fix(login.py): handle exceptions in login_to_get_access_token function to provide more detailed error messages

🐛 fix(users.py): only hash password if user is a superuser to prevent regular users from changing their password
This commit is contained in:
Gabriel Luiz Freitas Almeida 2023-09-25 19:34:17 -03:00
commit 1e0f81c135
2 changed files with 21 additions and 11 deletions

View file

@ -23,14 +23,22 @@ async def login_to_get_access_token(
db: Session = Depends(get_session), db: Session = Depends(get_session),
# _: Session = Depends(get_current_active_user) # _: Session = Depends(get_current_active_user)
): ):
if user := authenticate_user(form_data.username, form_data.password, db): try:
return create_user_tokens(user_id=user.id, db=db, update_last_login=True) user = authenticate_user(form_data.username, form_data.password, db)
else:
if user:
return create_user_tokens(user_id=user.id, db=db, update_last_login=True)
else:
raise HTTPException(
status_code=status.HTTP_401_UNAUTHORIZED,
detail="Incorrect username or password",
headers={"WWW-Authenticate": "Bearer"},
)
except Exception as exc:
raise HTTPException( raise HTTPException(
status_code=status.HTTP_401_UNAUTHORIZED, status_code=status.HTTP_500_INTERNAL_SERVER_ERROR,
detail="Incorrect username or password", detail=str(exc),
headers={"WWW-Authenticate": "Bearer"}, ) from exc
)
@router.get("/auto_login") @router.get("/auto_login")

View file

@ -99,10 +99,12 @@ def patch_user(
raise HTTPException( raise HTTPException(
status_code=403, detail="You don't have the permission to update this user" status_code=403, detail="You don't have the permission to update this user"
) )
if user_update.password and not user.is_superuser: if user_update.password:
raise HTTPException( if not user.is_superuser:
status_code=400, detail="You can't change your password here" raise HTTPException(
) status_code=400, detail="You can't change your password here"
)
user_update.password = get_password_hash(user_update.password)
if user_db := get_user_by_id(session, user_id): if user_db := get_user_by_id(session, user_id):
return update_user(user_db, user_update, session) return update_user(user_db, user_update, session)