From c21cd4b18f1b8b0eaf918a8a96707bab88b215fe Mon Sep 17 00:00:00 2001 From: "SPRINX0\\prochazka" Date: Tue, 4 Feb 2025 16:01:50 +0100 Subject: [PATCH] security problem fix #1029 --- packages/api/src/auth/authProvider.js | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/packages/api/src/auth/authProvider.js b/packages/api/src/auth/authProvider.js index c13628ce8..00fa04d81 100644 --- a/packages/api/src/auth/authProvider.js +++ b/packages/api/src/auth/authProvider.js @@ -218,7 +218,7 @@ class LoginsProvider extends AuthProviderBase { }; } - if (password == process.env[`LOGIN_PASSWORD_${login}`]) { + if (password && password == process.env[`LOGIN_PASSWORD_${login}`]) { return { accessToken: jwt.sign( {