MDL-19269 Deleted internal auth users - handling is buggy; credit Martin Langhoff

This commit is contained in:
skodak
2009-09-26 20:17:23 +00:00
parent 3cc5c930cb
commit 9afbbd3834
+6 -5
View File
@@ -3139,14 +3139,15 @@ function authenticate_user_login($username, $password) {
error_log('[client '.getremoteaddr()."] $CFG->wwwroot Disabled Login: $username ".$_SERVER['HTTP_USER_AGENT']);
return false;
}
if (!empty($user->deleted)) {
add_to_log(0, 'login', 'error', 'index.php', $username);
error_log('[client '.getremoteaddr()."] $CFG->wwwroot Deleted Login: $username ".$_SERVER['HTTP_USER_AGENT']);
return false;
}
$auths = array($auth);
} else {
// check if there's a deleted record (cheaply)
if (get_field('user', 'id', 'username', $username, 'deleted', 1, '')) {
error_log('[client '.$_SERVER['REMOTE_ADDR']."] $CFG->wwwroot Deleted Login: $username ".$_SERVER['HTTP_USER_AGENT']);
return false;
}
$auths = $authsenabled;
$user = new object();
$user->id = 0; // User does not exist