Skip to content

Commit 7bd2697

Browse files
Merge pull request #62985 from nextcloud/backport/62982/stable32
[stable32] fix: Handle 2fa enforcement earlier
2 parents 8097741 + 1453437 commit 7bd2697

2 files changed

Lines changed: 24 additions & 7 deletions

File tree

‎lib/private/User/Session.php‎

Lines changed: 4 additions & 5 deletions
Original file line numberDiff line numberDiff line change
@@ -403,10 +403,8 @@ public function logClientIn($user,
403403
return false;
404404
}
405405

406-
if (!$isTokenPassword && $this->isTokenAuthEnforced()) {
407-
throw new PasswordLoginForbiddenException();
408-
}
409-
if (!$isTokenPassword && $this->isTwoFactorEnforced($user)) {
406+
if (!$isTokenPassword && ($this->isTokenAuthEnforced() || $this->isTwoFactorEnforced($user))) {
407+
$this->handleLoginFailed($throttler, $currentDelay, $remoteAddress, $user, $password);
410408
throw new PasswordLoginForbiddenException();
411409
}
412410

@@ -587,7 +585,8 @@ public function tryBasicAuthLogin(IRequest $request,
587585
// If credentials were provided, they need to be valid, otherwise we do boom
588586
throw new LoginException();
589587
} catch (PasswordLoginForbiddenException $ex) {
590-
// Nothing to do
588+
// If credentials were provided, they need to be valid, otherwise we do boom
589+
throw new LoginException(previous: $ex);
591590
}
592591
}
593592
return false;

‎tests/lib/User/SessionTest.php‎

Lines changed: 20 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -439,7 +439,7 @@ public function testLogClientInNoTokenPasswordWith2fa(): void {
439439
->method('getRemoteAddress')
440440
->willReturn('192.168.0.1');
441441
$this->throttler
442-
->expects($this->once())
442+
->expects($this->exactly(2))
443443
->method('sleepDelayOrThrowOnMax')
444444
->with('192.168.0.1');
445445
$this->throttler
@@ -448,6 +448,15 @@ public function testLogClientInNoTokenPasswordWith2fa(): void {
448448
->with('192.168.0.1')
449449
->willReturn(0);
450450

451+
$this->throttler
452+
->expects($this->once())
453+
->method('registerAttempt')
454+
->with('login', '192.168.0.1', ['user' => 'john']);
455+
$this->dispatcher
456+
->expects($this->once())
457+
->method('dispatchTyped')
458+
->with(new LoginFailed('john', 'doe'));
459+
451460
$userSession->logClientIn('john', 'doe', $request, $this->throttler);
452461
}
453462

@@ -551,7 +560,7 @@ public function testLogClientInNoTokenPasswordNo2fa(): void {
551560
->method('getRemoteAddress')
552561
->willReturn('192.168.0.1');
553562
$this->throttler
554-
->expects($this->once())
563+
->expects($this->exactly(2))
555564
->method('sleepDelayOrThrowOnMax')
556565
->with('192.168.0.1');
557566
$this->throttler
@@ -560,6 +569,15 @@ public function testLogClientInNoTokenPasswordNo2fa(): void {
560569
->with('192.168.0.1')
561570
->willReturn(0);
562571

572+
$this->throttler
573+
->expects($this->once())
574+
->method('registerAttempt')
575+
->with('login', '192.168.0.1', ['user' => 'john']);
576+
$this->dispatcher
577+
->expects($this->once())
578+
->method('dispatchTyped')
579+
->with(new LoginFailed('john', 'doe'));
580+
563581
$userSession->logClientIn('john', 'doe', $request, $this->throttler);
564582
}
565583

0 commit comments

Comments
 (0)