CAPTCHA求めるのは2fa認証が無効になっているときだけにした

2faのトークンは期限付きだから、CAPTCHA解いてる間に期限切れになる
This commit is contained in:
syuilo
2022-05-15 16:47:14 +09:00
parent 9783f2de67
commit 02a43a310f
2 changed files with 14 additions and 14 deletions

View File

@ -20,18 +20,6 @@ export default async (ctx: Koa.Context) => {
const instance = await fetchMeta(true);
if (instance.enableHcaptcha && instance.hcaptchaSecretKey) {
await verifyHcaptcha(instance.hcaptchaSecretKey, body['hcaptcha-response']).catch(e => {
ctx.throw(400, e);
});
}
if (instance.enableRecaptcha && instance.recaptchaSecretKey) {
await verifyRecaptcha(instance.recaptchaSecretKey, body['g-recaptcha-response']).catch(e => {
ctx.throw(400, e);
});
}
const username = body['username'];
const password = body['password'];
const token = body['token'];
@ -96,6 +84,18 @@ export default async (ctx: Koa.Context) => {
}
if (!profile.twoFactorEnabled) {
if (instance.enableHcaptcha && instance.hcaptchaSecretKey) {
await verifyHcaptcha(instance.hcaptchaSecretKey, body['hcaptcha-response']).catch(e => {
ctx.throw(400, e);
});
}
if (instance.enableRecaptcha && instance.recaptchaSecretKey) {
await verifyRecaptcha(instance.recaptchaSecretKey, body['g-recaptcha-response']).catch(e => {
ctx.throw(400, e);
});
}
if (same) {
signin(ctx, user);
return;