8000 [Security] User enabled status is checked before authentication · Issue #13994 · symfony/symfony · GitHub
[go: up one dir, main page]

Skip to content
[Security] User enabled status is checked before authentication #13994
Closed
@bananer

Description

@bananer

This means anybody can find out whether another user's account is enabled or not. Seems like a (minor) privacy leak to me.

I would it expect to only check after the authentication, so that the error message stays "wrong credentials" until the correct password is provided, versus the current state where "Account is disabled" is thrown with any password.

Metadata

Metadata

Assignees

No one assigned

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions

      0