This commit is contained in:
Huong Nguyen
2025-12-15 08:55:30 +07:00
2 changed files with 50 additions and 15 deletions
+42 -14
View File
@@ -467,18 +467,31 @@ class auth extends \auth_plugin_base {
$mappeduser = get_complete_user_data('id', $linkedlogin->get('userid'));
if ($mappeduser && $mappeduser->suspended) {
$failurereason = AUTH_LOGIN_SUSPENDED;
$event = \core\event\user_login_failed::create([
'userid' => $mappeduser->id,
'other' => [
'username' => $userinfo['username'],
'reason' => $failurereason
]
]);
$event->trigger();
$SESSION->loginerrormsg = get_string('invalidlogin');
$client->log_out();
redirect(new moodle_url('/login/index.php'));
// Check if there's another user with the same email that is not suspended.
$moodleuser = \core_user::get_user_by_email($userinfo['email'], '*', null, IGNORE_MULTIPLE);
if ($moodleuser->id == $mappeduser->id) {
$failurereason = AUTH_LOGIN_SUSPENDED;
$event = \core\event\user_login_failed::create([
'userid' => $mappeduser->id,
'other' => [
'username' => $userinfo['username'],
'reason' => $failurereason,
],
]);
$event->trigger();
$SESSION->loginerrormsg = get_string('invalidlogin');
$client->log_out();
redirect(new moodle_url('/login/index.php'));
} else if ($moodleuser && !$moodleuser->suspended) {
// Update the OAuth2 linked login to point to the active user account.
$linkedlogin->set('userid', $moodleuser->id);
$linkedlogin->set('timemodified', time());
$linkedlogin->update();
// Update user fields and continue with login.
$userinfo = $this->update_user($userinfo, $moodleuser);
$userwasmapped = true;
}
} else if ($mappeduser && ($mappeduser->confirmed || !$issuer->get('requireconfirmation'))) {
// Update user fields.
$userinfo = $this->update_user($userinfo, $mappeduser);
@@ -508,7 +521,6 @@ class auth extends \auth_plugin_base {
redirect(new moodle_url('/login/index.php'));
}
if (!$issuer->is_valid_login_domain($oauthemail)) {
// Trigger login failed event.
$failurereason = AUTH_LOGIN_UNAUTHORISED;
@@ -524,8 +536,24 @@ class auth extends \auth_plugin_base {
if (!$userwasmapped) {
// No defined mapping - we need to see if there is an existing account with the same email.
$moodleuser = \core_user::get_user_by_email($userinfo['email'], '*', null, IGNORE_MULTIPLE);
// Ensure we don't link a login for a suspended user.
if (!empty($moodleuser) && $moodleuser->suspended) {
$failurereason = AUTH_LOGIN_SUSPENDED;
$event = \core\event\user_login_failed::create([
'userid' => $moodleuser->id,
'other' => [
'username' => $userinfo['email'],
'reason' => $failurereason,
],
]);
$event->trigger();
$SESSION->loginerrormsg = get_string('invalidlogin');
$client->log_out();
redirect(new moodle_url('/login/index.php'));
}
$moodleuser = \core_user::get_user_by_email($userinfo['email']);
if (!empty($moodleuser)) {
if ($issuer->get('requireconfirmation')) {
$PAGE->set_url('/auth/oauth2/confirm-link-login.php');
+8 -1
View File
@@ -156,7 +156,14 @@ class user {
$mnethostid = $CFG->mnet_localhost_id;
}
return $DB->get_record('user', ['email' => $email, 'mnethostid' => $mnethostid], $fields, $strictness);
// Build SQL query to prioritise active users.
$sql = "SELECT $fields
FROM {user}
WHERE email = :email AND mnethostid = :mnethostid
ORDER BY suspended ASC, timecreated DESC";
$params = ['email' => $email, 'mnethostid' => $mnethostid];
// Return the first user matching the query criteria.
return $DB->get_record_sql($sql, $params, $strictness);
}
/**