From f83e2553fdb9c14712af8500cb6fa57222e198c5 Mon Sep 17 00:00:00 2001 From: qwertyforce <44163887+qwertyforce@users.noreply.github.com> Date: Tue, 20 Oct 2020 11:06:28 +0300 Subject: [PATCH] login/signup 403 --- server/routes/login.ts | 2 +- server/routes/signup.ts | 2 +- 2 files changed, 2 insertions(+), 2 deletions(-) diff --git a/server/routes/login.ts b/server/routes/login.ts index 51a21ac..ab2de76 100644 --- a/server/routes/login.ts +++ b/server/routes/login.ts @@ -23,7 +23,7 @@ async function login(req:Request,res:Response) { const users = await db_ops.activated_user.find_user_by_email(email); if (users.length === 0) { await crypto_ops.check_password("Random_text_qwfqwfg", "$2b$10$xKgSc736RxzT76ZMGyXMLe1Dge99d4PLyUOv60jpywAWJwftYcgjK"); // PROTECTION AGAINST TIMING ATTACK - res.json({ + res.status(403).json({ message: MESSAGE_FOR_AUTH_ERROR }) } else { diff --git a/server/routes/signup.ts b/server/routes/signup.ts index 6a2b7ce..41c62e3 100644 --- a/server/routes/signup.ts +++ b/server/routes/signup.ts @@ -31,7 +31,7 @@ async function signup(req:Request,res:Response) { }) } else { console.log(users) - res.json({ + res.status(403).json({ message: 'User with same email is already registered' }) }