Skip to content

Commit 19094aa

Browse files
authored
Merge pull request #24 from robscllc/master
verify both username and password in examples
2 parents cea3c4b + 2818923 commit 19094aa

File tree

9 files changed

+10
-10
lines changed

9 files changed

+10
-10
lines changed

examples/additional_data_in_access_token.py

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -23,7 +23,7 @@ def add_claims_to_access_token(identity):
2323
def login():
2424
username = request.json.get('username', None)
2525
password = request.json.get('password', None)
26-
if username != 'test' and password != 'test':
26+
if username != 'test' or password != 'test':
2727
return jsonify({"msg": "Bad username or password"}), 401
2828

2929
ret = {'access_token': create_access_token(username)}

examples/blacklist.py

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -35,7 +35,7 @@
3535
def login():
3636
username = request.json.get('username', None)
3737
password = request.json.get('password', None)
38-
if username != 'test' and password != 'test':
38+
if username != 'test' or password != 'test':
3939
return jsonify({"msg": "Bad username or password"}), 401
4040

4141
ret = {

examples/csrf_protection_with_cookies.py

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -43,7 +43,7 @@
4343
def login():
4444
username = request.json.get('username', None)
4545
password = request.json.get('password', None)
46-
if username != 'test' and password != 'test':
46+
if username != 'test' or password != 'test':
4747
return jsonify({'login': False}), 401
4848

4949
# Create the tokens we will be sending back to the user

examples/jwt_in_cookie.py

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -36,7 +36,7 @@
3636
def login():
3737
username = request.json.get('username', None)
3838
password = request.json.get('password', None)
39-
if username != 'test' and password != 'test':
39+
if username != 'test' or password != 'test':
4040
return jsonify({'login': False}), 401
4141

4242
# Create the tokens we will be sending back to the user

examples/loaders.py

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -23,7 +23,7 @@ def my_expired_token_callback():
2323
def login():
2424
username = request.json.get('username', None)
2525
password = request.json.get('password', None)
26-
if username != 'test' and password != 'test':
26+
if username != 'test' or password != 'test':
2727
return jsonify({"msg": "Bad username or password"}), 401
2828

2929
ret = {'access_token': create_access_token(username)}

examples/refresh_tokens.py

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -12,7 +12,7 @@
1212
def login():
1313
username = request.json.get('username', None)
1414
password = request.json.get('password', None)
15-
if username != 'test' and password != 'test':
15+
if username != 'test' or password != 'test':
1616
return jsonify({"msg": "Bad username or password"}), 401
1717

1818
# Use create_access_token() and create_refresh_token() to create our

examples/simple.py

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -15,7 +15,7 @@
1515
def login():
1616
username = request.json.get('username', None)
1717
password = request.json.get('password', None)
18-
if username != 'test' and password != 'test':
18+
if username != 'test' or password != 'test':
1919
return jsonify({"msg": "Bad username or password"}), 401
2020

2121
# Identity can be any data that is json serializable

examples/token_freshness.py

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -14,7 +14,7 @@
1414
def login():
1515
username = request.json.get('username', None)
1616
password = request.json.get('password', None)
17-
if username != 'test' and password != 'test':
17+
if username != 'test' or password != 'test':
1818
return jsonify({"msg": "Bad username or password"}), 401
1919

2020
# create_access_token supports an optional 'fresh' argument,
@@ -37,7 +37,7 @@ def login():
3737
def fresh_login():
3838
username = request.json.get('username', None)
3939
password = request.json.get('password', None)
40-
if username != 'test' and password != 'test':
40+
if username != 'test' or password != 'test':
4141
return jsonify({"msg": "Bad username or password"}), 401
4242

4343
new_token = create_access_token(identity=username, fresh=True)

examples/tokens_from_complex_objects.py

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -37,7 +37,7 @@ def user_identity_lookup(user):
3737
def login():
3838
username = request.json.get('username', None)
3939
password = request.json.get('password', None)
40-
if username != 'test' and password != 'test':
40+
if username != 'test' or password != 'test':
4141
return jsonify({"msg": "Bad username or password"}), 401
4242

4343
# Create an example UserObject

0 commit comments

Comments
 (0)