-
Type: Improvement
-
Status: Open (View Workflow)
-
Priority: Critical
-
Resolution: Unresolved
-
Affects Version/s: 2.1 Swallows
-
Fix Version/s: None
-
Labels:None
When authenticating user via REST Poulpe should distinguish the following two use cases:
1. Requested user cannot be found by username provided
2. Requested username exists, but provided password hash does not match expectations
I believe we can return we same response code for compatibility sake. Response text, however, should clearly indicate the difference for the client to know the reason for authentication denial.
- blocks
-
ANTARCTICLE-303 User can login with old password after changing
- Closed