Skip to content

Authentication not validating password at all. #8

@Fa2y

Description

@Fa2y

if user and verify_password(password, user.password):

authentication.py:70: RuntimeWarning: coroutine 'verify_password' was never awaited
  if user and verify_password(password, user.password):
RuntimeWarning: Enable tracemalloc to get the object allocation traceback
INFO:     127.0.0.1:46472 - "POST /token HTTP/1.1" 200 OK

verify_password is an async function and should be awaited, not awaiting it will result in returning a coroutine object that render the condition pointless as it will give valid token for any true username provided.

Metadata

Metadata

Assignees

Labels

bugSomething isn't working

Projects

No projects

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions