Welcome to mirror list, hosted at ThFree Co, Russian Federation.

gitlab.com/gitlab-org/gitlab-foss.git - Unnamed repository; edit this file 'description' to name the repository.
summaryrefslogtreecommitdiff
diff options
context:
space:
mode:
Diffstat (limited to 'config/initializers/doorkeeper.rb')
-rw-r--r--config/initializers/doorkeeper.rb9
1 files changed, 5 insertions, 4 deletions
diff --git a/config/initializers/doorkeeper.rb b/config/initializers/doorkeeper.rb
index f343c20dfe4..3572c30cdd3 100644
--- a/config/initializers/doorkeeper.rb
+++ b/config/initializers/doorkeeper.rb
@@ -22,13 +22,14 @@ Doorkeeper.configure do
end
end
- resource_owner_from_credentials do |routes|
- user = Gitlab::Auth.find_with_user_password(params[:username], params[:password], increment_failed_attempts: true)
-
+ resource_owner_from_credentials do |_routes|
+ user = User.find_by_login(params[:username])
next unless user
+
+ next if user.password_automatically_set?
next if user.two_factor_enabled? || Gitlab::Auth::TwoFactorAuthVerifier.new(user).two_factor_authentication_enforced?
- user
+ Gitlab::Auth.find_with_user_password(params[:username], params[:password], increment_failed_attempts: true)
end
# If you want to restrict access to the web interface for adding oauth authorized applications, you need to declare the block below.