Password grant type: access token for blocked account

Created on 13 January 2022, over 2 years ago
Updated 22 May 2023, about 1 year ago

Firstly, tahks for your job!!!

Problem/Motivation

It was the great idea in #2841236: Password grant endpoint: do not allow authentication, when user is blocked β†’ but it is still allowed to get access token for blocked user in v5.2.
#2976463: Blocked user Bearer token regeneration issue β†’ works as expected, but why the module allows to obtain an access token when account is already blocked?

Proposed resolution

I propose use the proposed method from #2841236: Password grant endpoint: do not allow authentication, when user is blocked β†’ if it's possible. Otherwise no way to recognize the user status before tne next request with obtained access token.

πŸ› Bug report
Status

RTBC

Version

5.2

Component

Code

Created by

πŸ‡·πŸ‡ΊRussia validoll Ekaterinburg

Live updates comments and jobs are added and updated live.
Sign in to follow issues

Comments & Activities

Not all content is available!

It's likely this issue predates Contrib.social: some issue and comment data are missing.

Production build 0.69.0 2024