Skip to content

Ensure login username is provided as string value #23117

New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Merged
merged 1 commit into from
Mar 12, 2025
Merged

Ensure login username is provided as string value #23117

merged 1 commit into from
Mar 12, 2025

Conversation

sgiehl
Copy link
Member

@sgiehl sgiehl commented Mar 11, 2025

Description:

providing the login as an array in the login/logme request currently results in a fatal error. With this PR a string will be expected, causing a proper error to be shown if an array is provided instead.

fixes #22929

Review

@sgiehl sgiehl added this to the 5.4.0 milestone Mar 11, 2025
@sgiehl sgiehl marked this pull request as ready for review March 11, 2025 15:17
@sgiehl sgiehl requested a review from a team March 11, 2025 15:17
@sgiehl sgiehl added the Bug For errors / faults / flaws / inconsistencies etc. label Mar 11, 2025
@sgiehl sgiehl merged commit 4dbd523 into 5.x-dev Mar 12, 2025
25 of 27 checks passed
@sgiehl sgiehl deleted the dev-18846 branch March 12, 2025 09:35
caddoo added a commit that referenced this pull request May 2, 2025
* Cherry pick ubuntu-24.04 update excl. submodule update (#23097)

* Update expected test results

* Ensure login username is provided as string value (#23117)

* Prevent automated linking in emails (#23248)

* Prevent automated linking in emails

* prevent linking on some more elements

* add some tests

---------

Co-authored-by: caddoo <1169490+caddoo@users.noreply.github.com>

* Improve handling of prefixUrl parameter in API.listAllMethods (#23247)

* Fix escaping in realtime report (#23245)

* Ensure all translations required for password confirmation are always loaded (#23176)

* Suppress errors when trying to access javaEnabled property (#23161)

Co-authored-by: caddoo <matthew.caddoo@gmail.com>

* Ensure to discard campaign names with invalid type (#23229)

* Prevent concurrency when removing sites (#23230)

* Prevent warning when no email is set for current user (#23228)

* Improve region name fetching (#23235)

* Unset actionsByVisitId after consumption (#23234)

* Use https URLs (#23072)

* Use https URLs

* Build vue files

* use matomo.org instead of piwik.org in some links

* updates expected UI test file

---------

Co-authored-by: innocraft-automation <innocraft-automation@users.noreply.github.com>

* Update screenshot

* Tweak regex for host checks

---------

Co-authored-by: Marc Neudert <marc@innocraft.com>
Co-authored-by: Stefan Giehl <stefan@matomo.org>
Co-authored-by: caddoo <1169490+caddoo@users.noreply.github.com>
Co-authored-by: caddoo <matthew.caddoo@gmail.com>
Co-authored-by: innocraft-automation <innocraft-automation@users.noreply.github.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
Bug For errors / faults / flaws / inconsistencies etc.
Development

Successfully merging this pull request may close these issues.

[Bug] BruteForce login logic doesn't validate login type
2 participants