Fix empty password breach

This commit is contained in:
Jerome Lebleu 2013-12-28 18:13:43 +01:00
parent eb265396b3
commit a1683dc4cd

View file

@ -42,8 +42,10 @@ def http_exec(request, **kwargs):
# Simple HTTP auth
elif installed:
authorized = request.getUser() == 'admin'
authorized = False
pwd = request.getPassword()
if request.getUser() == 'admin' and pwd != '':
authorized = True
if dev and 'api_key' in request.args:
pwd = request.args['api_key'][0]
authorized = True