From 48d5a1bcd3ea4dde55579978ab8801f3a5808ce5 Mon Sep 17 00:00:00 2001 From: Alexander Zobnin Date: Fri, 5 Jul 2019 12:35:04 +0300 Subject: [PATCH] OAuth: deny login for disabled users (#17957) --- pkg/api/login_oauth.go | 5 +++++ 1 file changed, 5 insertions(+) diff --git a/pkg/api/login_oauth.go b/pkg/api/login_oauth.go index 9c4bdf5d85e..851a6c84c60 100644 --- a/pkg/api/login_oauth.go +++ b/pkg/api/login_oauth.go @@ -191,6 +191,11 @@ func (hs *HTTPServer) OAuthLogin(ctx *m.ReqContext) { return } + if cmd.Result.IsDisabled { + hs.redirectWithError(ctx, login.ErrUserDisabled) + return + } + // login hs.loginUserWithUser(cmd.Result, ctx)