Merge pull request #62 from jeromelebleu/dev

Fix empty password breach
This commit is contained in:
Jérôme Lebleu 2013-12-28 09:18:35 -08:00
commit 65270dba7b

View file

@ -42,8 +42,10 @@ def http_exec(request, **kwargs):
# Simple HTTP auth
elif installed:
authorized = request.getUser() == 'admin'
authorized = False
pwd = request.getPassword()
if request.getUser() == 'admin' and pwd != '':
authorized = True
if dev and 'api_key' in request.args:
pwd = request.args['api_key'][0]
authorized = True