Fixed 2FA enforcement on login screen.
This commit is contained in:
@@ -21,7 +21,7 @@ class SessionsController < ApplicationController
|
|||||||
flash[:alert] = "Your account has been disabled!"
|
flash[:alert] = "Your account has been disabled!"
|
||||||
elsif user.banned?
|
elsif user.banned?
|
||||||
flash[:alert] = "You are banned!"
|
flash[:alert] = "You are banned!"
|
||||||
elsif user.totp_enabled && !TOTP.valid?(user.totp_code, params[:totp_code])
|
elsif user.totp_enabled && !TOTP.valid?(user.totp_secret, params[:totp_code].to_i)
|
||||||
flash[:alert] = "You're doing it wrong!"
|
flash[:alert] = "You're doing it wrong!"
|
||||||
render action: 'new'
|
render action: 'new'
|
||||||
return
|
return
|
||||||
|
|||||||
Reference in New Issue
Block a user