We read every piece of feedback, and take your input very seriously.
To see all available qualifiers, see our documentation.
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Authenticate using "strategy": "local" without providing anything but a password matching the password of the first user in database.
"strategy": "local"
$ curl 'http://localhost:3030/authentication/' -H 'Content-Type: application/json' --data-binary '{"password": "S0m3Pa22wOrd", "strategy": "local"}' -o - | jq . { "accessToken": "eyJhbGciO ... WOSRycz1lJQJNUk285VklI", "authentication": { "strategy": "local" }, "user": { "id": 1, "email": "[email protected]", "createdAt": "2019-09-12T14:31:03.925Z", "updatedAt": "2019-09-12T14:31:03.925Z" } }
Authentication should not be possible without providing a Username
If the password compares to the passwordHash of the first User, authentication succeeds
Module versions (especially the part that's not working): [email protected]
NodeJS version: v12.10.0
Operating System: Windows 10
Browser Version: curl 7.50.3 (i686-pc-cygwin) libcurl/7.50.3 OpenSSL/1.0.1g zlib/1.2.7 libidn/1.26 libssh2/1.7.0
React Native Version: -
Module Loader: -
The text was updated successfully, but these errors were encountered:
fix: LocalStrategy authenticates without username
eadb191
feathersjs#1559
fix: LocalStrategy authenticates without username (#1560)
2b258fd
#1559
Successfully merging a pull request may close this issue.
Steps to reproduce
Authenticate using
"strategy": "local"
without providing anything but a password matching the password of the first user in database.Expected behavior
Authentication should not be possible without providing a Username
Actual behavior
If the password compares to the passwordHash of the first User, authentication succeeds
System configuration
Module versions (especially the part that's not working): [email protected]
NodeJS version: v12.10.0
Operating System: Windows 10
Browser Version: curl 7.50.3 (i686-pc-cygwin) libcurl/7.50.3 OpenSSL/1.0.1g zlib/1.2.7 libidn/1.26 libssh2/1.7.0
React Native Version: -
Module Loader: -
The text was updated successfully, but these errors were encountered: