From b7cc18ee98e568cdf31ba41d3eafd21344a421db Mon Sep 17 00:00:00 2001 From: abdellani Date: Fri, 15 Mar 2019 18:33:07 +0100 Subject: [PATCH] Show error message when a disabled user tries to authenticate --- src/resolvers/user_management.js | 10 ++++------ 1 file changed, 4 insertions(+), 6 deletions(-) diff --git a/src/resolvers/user_management.js b/src/resolvers/user_management.js index ebb50f0b1..c81d12c37 100644 --- a/src/resolvers/user_management.js +++ b/src/resolvers/user_management.js @@ -46,17 +46,15 @@ export default { if ( currentUser && (await bcrypt.compareSync(password, currentUser.password)) && - currentUser.disabled == false + !currentUser.disabled ) { delete currentUser.password return encode(currentUser) - } - else if (currentUser && + } else if (currentUser && currentUser.disabled - ){ + ) { throw new AuthenticationError('Your account has been disabled.') - } - else { + } else { throw new AuthenticationError('Incorrect email address or password.') } },