mirror of
https://github.com/spacebarchat/server.git
synced 2024-11-05 18:32:33 +01:00
Don't let users undisable their accounts
This commit is contained in:
parent
bc086a070c
commit
cd84412c92
@ -66,9 +66,6 @@ router.post(
|
||||
});
|
||||
|
||||
if (undelete) {
|
||||
// undelete refers to un'disable' here
|
||||
if (user.disabled)
|
||||
await User.update({ id: user.id }, { disabled: false });
|
||||
if (user.deleted)
|
||||
await User.update({ id: user.id }, { deleted: false });
|
||||
} else {
|
||||
@ -77,13 +74,14 @@ router.post(
|
||||
message: "This account is scheduled for deletion.",
|
||||
code: 20011,
|
||||
});
|
||||
if (user.disabled)
|
||||
return res.status(400).json({
|
||||
message: req.t("auth:login.ACCOUNT_DISABLED"),
|
||||
code: 20013,
|
||||
});
|
||||
}
|
||||
|
||||
if (user.disabled)
|
||||
return res.status(400).json({
|
||||
message: req.t("auth:login.ACCOUNT_DISABLED"),
|
||||
code: 20013,
|
||||
});
|
||||
|
||||
// the salt is saved in the password refer to bcrypt docs
|
||||
const same_password = await bcrypt.compare(
|
||||
password,
|
||||
|
Loading…
Reference in New Issue
Block a user