From c44856d4d0daa4be1e96ea90d3daedeaeddbfd08 Mon Sep 17 00:00:00 2001 From: Waqas Hussain Date: Tue, 15 Jun 2010 09:11:10 +0500 Subject: mod_auth_internal_hashed: Don't assume user doesn't exist if no recognizable authentication data is found. --- plugins/mod_auth_internal_hashed.lua | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) (limited to 'plugins') diff --git a/plugins/mod_auth_internal_hashed.lua b/plugins/mod_auth_internal_hashed.lua index f8e9b00c..81dfe688 100644 --- a/plugins/mod_auth_internal_hashed.lua +++ b/plugins/mod_auth_internal_hashed.lua @@ -100,10 +100,10 @@ function new_hashpass_provider(host) log("debug", "account not found for username '%s' at host '%s'", username, module.host); return nil, "Auth failed. Invalid username"; end - if (account.hashpass == nil or string.len(account.hashpass) == 0) and (account.password == nil or string.len(account.password) == 0) then + --[[if (account.hashpass == nil or string.len(account.hashpass) == 0) and (account.password == nil or string.len(account.password) == 0) then log("debug", "account password not set or zero-length for username '%s' at host '%s'", username, module.host); return nil, "Auth failed. Password invalid."; - end + end]] return true; end -- cgit v1.2.3