hotsh / rstat.us

Simple microblogging network based on the ostatus protocol.
http://rstat.us/
Other
722 stars 215 forks source link

Fixes issue #532. Don't even try authenticating by checking hashed_passw... #724

Closed carols10cents closed 11 years ago

carols10cents commented 11 years ago

...ord if there isn't one-- just fail.

Created a contrived test that sets up this scenario since it doesn't seem to happen with new users anymore?

wilkie commented 11 years ago

Seems fair. Although... how did it happen in the first place? Any idea?

carols10cents commented 11 years ago

I have no idea. Seems like the password setting and authenticating code has been this way since 815b3873, we just may not have known that it happens. But now, as people leave rstat.us for a while then come back and forget if they've signed up with twitter or with username/pw, and now that we have airbrake catching exceptions, we know about it...?

wilkie commented 11 years ago

Alright. Sounds fine to me. Can't hurt any. :)