Skip to content
Snippets Groups Projects
Select Git revision
  • move-gl-dropdown
  • improve-table-pagination-spec
  • move-markdown-preview
  • winh-fix-merge-request-spec
  • master default
  • index-namespaces-lower-name
  • winh-single-karma-test
  • 10-3-stable
  • 36782-replace-team-user-role-with-add_role-user-in-specs
  • winh-modal-internal-state
  • tz-ide-file-icons
  • 38869-milestone-select
  • update-autodevops-template
  • jivl-activate-repo-cookie-preferences
  • qa-add-deploy-key
  • docs-move-article-ldap
  • 40780-choose-file
  • 22643-manual-job-page
  • refactor-cluster-show-page-conservative
  • dm-sidekiq-versioning
  • v10.4.0.pre
  • v10.3.0
  • v10.3.0-rc5
  • v10.3.0-rc4
  • v10.3.0-rc3
  • v10.3.0-rc2
  • v10.2.5
  • v10.3.0-rc1
  • v10.0.7
  • v10.1.5
  • v10.2.4
  • v10.2.3
  • v10.2.2
  • v10.2.1
  • v10.3.0.pre
  • v10.2.0
  • v10.2.0-rc4
  • v10.2.0-rc3
  • v10.1.4
  • v10.2.0-rc2
40 results

sessions_controller_spec.rb

Blame
Forked from GitLab.org / GitLab FOSS
Source project has a limited visibility.
  • Grzegorz Bizon's avatar
    00da609c
    Fix 2FA authentication spoofing vulnerability · 00da609c
    Grzegorz Bizon authored
    This commit attempts to change default user search scope if otp_user_id
    session variable has been set. If it is present, it means that user has
    2FA enabled, and has already been verified with login and password. In
    this case we should look for user with otp_user_id first, before picking
    it up by login.
    00da609c
    History
    Fix 2FA authentication spoofing vulnerability
    Grzegorz Bizon authored
    This commit attempts to change default user search scope if otp_user_id
    session variable has been set. If it is present, it means that user has
    2FA enabled, and has already been verified with login and password. In
    this case we should look for user with otp_user_id first, before picking
    it up by login.