From c86c75cc2b8f5440b4fdaa021e9ff06410c3d3b9 Mon Sep 17 00:00:00 2001 From: mvdbeek Date: Tue, 25 Feb 2020 11:31:58 +0100 Subject: [PATCH 1/2] Fix login to accounts using different email capitalization https://github.com/galaxyproject/galaxy/pull/8631 added case-insensitive matches to user emails. If two accounts with different email capitalizations exist one of them will be picked at random for login. To fix this we first check for exact match and only if there is no direct match we lowercase the comparison. --- lib/galaxy/managers/users.py | 4 +++- lib/galaxy/webapps/galaxy/controllers/user.py | 7 ++++++- 2 files changed, 9 insertions(+), 2 deletions(-) diff --git a/lib/galaxy/managers/users.py b/lib/galaxy/managers/users.py index f3f9ba94d0f..2ad6457a2c0 100644 --- a/lib/galaxy/managers/users.py +++ b/lib/galaxy/managers/users.py @@ -489,7 +489,9 @@ class UserManager(base.ModelManager, deletable.PurgableManagerMixin): return "Failed to produce password reset token. User not found." def get_reset_token(self, trans, email): - reset_user = trans.sa_session.query(self.app.model.User).filter(func.lower(self.app.model.User.table.c.email) == email.lower()).first() + reset_user = trans.sa_session.query(self.app.model.User).filter(self.app.model.User.table.c.email == email.lower()).first() + if not reset_user and email != email.lower(): + reset_user = trans.sa_session.query(self.app.model.User).filter(func.lower(self.app.model.User.table.c.email) == email.lower()).first() if reset_user: prt = self.app.model.PasswordResetToken(reset_user) trans.sa_session.add(prt) diff --git a/lib/galaxy/webapps/galaxy/controllers/user.py b/lib/galaxy/webapps/galaxy/controllers/user.py index 4e75d5a91ea..071ee286de3 100644 --- a/lib/galaxy/webapps/galaxy/controllers/user.py +++ b/lib/galaxy/webapps/galaxy/controllers/user.py @@ -135,9 +135,14 @@ class User(BaseUIController, UsesFormDefinitionsMixin, CreatesApiKeysMixin): if not login or not password: return self.message_exception(trans, "Please specify a username and password.") user = trans.sa_session.query(trans.app.model.User).filter(or_( - func.lower(trans.app.model.User.table.c.email) == login.lower(), + trans.app.model.User.table.c.email == login, trans.app.model.User.table.c.username == login )).first() + if not user and login.lower() != login: + user = trans.sa_session.query(trans.app.model.User).filter(or_( + func.lower(trans.app.model.User.table.c.email) == login.lower(), + trans.app.model.User.table.c.username == login + )).first() log.debug("trans.app.config.auth_config_file: %s" % trans.app.config.auth_config_file) if user is None: message, user = self.__autoregistration(trans, login, password) From d5be9b3ae5cf091bb518a717b9c7fda8204973ef Mon Sep 17 00:00:00 2001 From: Marius van den Beek Date: Tue, 25 Feb 2020 16:29:32 +0100 Subject: [PATCH 2/2] Don't check username again Co-Authored-By: Nicola Soranzo --- lib/galaxy/webapps/galaxy/controllers/user.py | 7 +++---- 1 file changed, 3 insertions(+), 4 deletions(-) diff --git a/lib/galaxy/webapps/galaxy/controllers/user.py b/lib/galaxy/webapps/galaxy/controllers/user.py index 071ee286de3..7cf207f7a8b 100644 --- a/lib/galaxy/webapps/galaxy/controllers/user.py +++ b/lib/galaxy/webapps/galaxy/controllers/user.py @@ -139,10 +139,9 @@ class User(BaseUIController, UsesFormDefinitionsMixin, CreatesApiKeysMixin): trans.app.model.User.table.c.username == login )).first() if not user and login.lower() != login: - user = trans.sa_session.query(trans.app.model.User).filter(or_( - func.lower(trans.app.model.User.table.c.email) == login.lower(), - trans.app.model.User.table.c.username == login - )).first() + user = trans.sa_session.query(trans.app.model.User).filter( + func.lower(trans.app.model.User.table.c.email) == login.lower() + ).first() log.debug("trans.app.config.auth_config_file: %s" % trans.app.config.auth_config_file) if user is None: message, user = self.__autoregistration(trans, login, password)