Skip to content

Commit

Permalink
Merge pull request #28413 from nextcloud/fix/app-token-login-name-mis…
Browse files Browse the repository at this point in the history
…match-logging
  • Loading branch information
skjnldsv authored Aug 18, 2021
2 parents 2c5d308 + a143337 commit 7ab39ef
Showing 1 changed file with 6 additions and 1 deletion.
7 changes: 6 additions & 1 deletion lib/private/User/Session.php
Original file line number Diff line number Diff line change
Expand Up @@ -788,9 +788,14 @@ private function validateToken($token, $user = null) {

// Check if login names match
if (!is_null($user) && $dbToken->getLoginName() !== $user) {
// TODO: this makes it imposssible to use different login names on browser and client
// TODO: this makes it impossible to use different login names on browser and client
// e.g. login by e-mail '[email protected]' on browser for generating the token will not
// allow to use the client token with the login name 'user'.
$this->logger->error('App token login name does not match', [
'tokenLoginName' => $dbToken->getLoginName(),
'sessionLoginName' => $user,
]);

return false;
}

Expand Down

0 comments on commit 7ab39ef

Please sign in to comment.