mirror of
https://github.com/nikdoof/test-auth.git
synced 2025-12-14 06:42:16 +00:00
Don't allow resets of Service Acccounts that don't need a password
This commit is contained in:
@@ -215,7 +215,8 @@ def service_reset(request, serviceid=0):
|
||||
except ServiceAccount.DoesNotExist:
|
||||
return redirect('sso.views.profile')
|
||||
|
||||
if not acc.active:
|
||||
# If the account is inactive, or the service doesn't require a password, redirect
|
||||
if not acc.active or ('require_password' in acc.service.settings and not acc.service.settings['require_password']):
|
||||
return redirect('sso.views.profile')
|
||||
|
||||
if acc.user == request.user:
|
||||
|
||||
Reference in New Issue
Block a user