-
Notifications
You must be signed in to change notification settings - Fork 298
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Omit detailedMessage from login errors #3136
Omit detailedMessage from login errors #3136
Conversation
@jinapurapu , could you check the |
f2ddbb2
to
f3987ec
Compare
@jinapurapu there are some test failures , may be related to the messages |
763a205
to
aa054bc
Compare
@jinapurapu Please change only the messages in Login APIs, the errors from Object browser are required as there are required to handle a specific corner case |
ac47011
to
5dca280
Compare
…stinguishable between valid and invalid accessKeys Cleanup Cleanup Gofumpt Removed detailed errors Debugging sso test Remove detailedMessage from login related errors passed to Console Replaced user_loin with master Updated tests to reflect removal of detailedMessage for login errors Removed detailedMessage check from SSO badLogin test Replaced detailed messsage for LoginNotAllowed Replaced detailed message for accessdenied error removed commented lines
8244644
to
41bd4b5
Compare
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
LGTM
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Thanks for addressing the comments, LGTM
Avoids passing detailed error to frontend login errors, no longer differentiable between existing/non-existing Users.
Existing user, wrong password:
data:image/s3,"s3://crabby-images/b531a/b531a57d6799997f242b7207005334397f0b79d7" alt="Screenshot 2023-12-05 at 2 32 37 PM"
User doesn't exist:
Part of https://github.com/miniohq/engineering/issues/1306