From eacb0a452e8fd6bc7f44e056a5373189376d6e84 Mon Sep 17 00:00:00 2001 From: abdellani Date: Fri, 15 Mar 2019 18:33:07 +0100 Subject: [PATCH] Show error message when a disabled user tries to authenticate --- src/resolvers/user_management.js | 10 ++++------ 1 file changed, 4 insertions(+), 6 deletions(-) diff --git a/src/resolvers/user_management.js b/src/resolvers/user_management.js index ebb50f0b1..26dfb81db 100644 --- a/src/resolvers/user_management.js +++ b/src/resolvers/user_management.js @@ -46,17 +46,15 @@ export default { if ( currentUser && (await bcrypt.compareSync(password, currentUser.password)) && - currentUser.disabled == false + !currentUser.disabled ) { delete currentUser.password return encode(currentUser) - } - else if (currentUser && + } else if (currentUser && currentUser.disabled - ){ + ) { throw new AuthenticationError('Your account has been disabled.') - } - else { + } else { throw new AuthenticationError('Incorrect email address or password.') } },