Merge pull request #203 from DerDackel/nopasswords

Remove password from log message upon login failure
This commit is contained in:
Lunny Xiao 2014-05-19 16:16:07 +08:00
commit fdc6b64f15

View File

@ -105,7 +105,7 @@ func SignInPost(ctx *middleware.Context, form auth.LogInForm) {
user, err = models.LoginUser(form.UserName, form.Password)
if err != nil {
if err == models.ErrUserNotExist {
log.Trace("%s Log in failed: %s/%s", ctx.Req.RequestURI, form.UserName, form.Password)
log.Trace("%s Log in failed: %s", ctx.Req.RequestURI, form.UserName)
ctx.RenderWithErr("Username or password is not correct", "user/signin", &form)
return
}