mirror of
				https://github.com/mail-in-a-box/mailinabox.git
				synced 2025-10-31 19:00:54 +00:00 
			
		
		
		
	Only update mru_token for matched mfa row
This commit is contained in:
		
							parent
							
								
									be5032ffbe
								
							
						
					
					
						commit
						ada2167d08
					
				| @ -43,9 +43,9 @@ def enable_mfa(email, type, secret, token, label, env): | ||||
| 	c.execute('INSERT INTO mfa (user_id, type, secret, label) VALUES (?, ?, ?, ?)', (get_user_id(email, c), type, secret, label)) | ||||
| 	conn.commit() | ||||
| 
 | ||||
| def set_mru_token(email, token, env): | ||||
| def set_mru_token(email, mfa_id, token, env): | ||||
| 	conn, c = open_database(env, with_connection=True) | ||||
| 	c.execute('UPDATE mfa SET mru_token=? WHERE user_id=?', (token, get_user_id(email, c))) | ||||
| 	c.execute('UPDATE mfa SET mru_token=? WHERE user_id=? AND id=?', (token, get_user_id(email, c), mfa_id)) | ||||
| 	conn.commit() | ||||
| 
 | ||||
| def disable_mfa(email, mfa_id, env): | ||||
| @ -127,7 +127,7 @@ def validate_auth_mfa(email, request, env): | ||||
| 				continue | ||||
| 
 | ||||
| 			# On success, record the token to prevent a replay attack. | ||||
| 			set_mru_token(email, token, env) | ||||
| 			set_mru_token(email, mfa_mode['id'], token, env) | ||||
| 			return (True, []) | ||||
| 
 | ||||
| 	# On a failed login, indicate failure and any hints for what the user can do instead. | ||||
|  | ||||
		Loading…
	
		Reference in New Issue
	
	Block a user