diff options
| author | Joshua M. Boniface <joshua@boniface.me> | 2019-04-18 17:58:54 -0400 |
|---|---|---|
| committer | GitHub <noreply@github.com> | 2019-04-18 17:58:54 -0400 |
| commit | 06a1e1f1664e6a4d7b552c8d230189e8f4a6f752 (patch) | |
| tree | 7dac80a080350bef7c12ae9971a81a2cad298e76 /MediaBrowser.Api/UserService.cs | |
| parent | cde737504905795da056babb573442fff77cceff (diff) | |
| parent | 31ad366aa93e8bc07f6e120320f3abd27d9dfd49 (diff) | |
Merge pull request #1244 from joshuaboniface/hotfix-authapi
Hotfix authapi
Diffstat (limited to 'MediaBrowser.Api/UserService.cs')
| -rw-r--r-- | MediaBrowser.Api/UserService.cs | 7 |
1 files changed, 6 insertions, 1 deletions
diff --git a/MediaBrowser.Api/UserService.cs b/MediaBrowser.Api/UserService.cs index a6849f75f..497800d26 100644 --- a/MediaBrowser.Api/UserService.cs +++ b/MediaBrowser.Api/UserService.cs @@ -379,10 +379,15 @@ namespace MediaBrowser.Api throw new ResourceNotFoundException("User not found"); } + if (!string.IsNullOrEmpty(request.Password) && string.IsNullOrEmpty(request.Pw)) + { + throw new MethodNotAllowedException("Hashed-only passwords are not valid for this API."); + } + return Post(new AuthenticateUserByName { Username = user.Name, - Password = request.Password, + Password = null, // This should always be null Pw = request.Pw }); } |
