Moritz Heiber 7e12aac61c Only allow token authentication with 2FA enabled (#2184)
* Don't allow for plain username/password authentication when 2FA is enabled

* Removed debugging statement

* Don't assume a token belongs to a given user, handle two-factor errors properly

* Simplified user/token matching, refactored error handling for two-factor authentication

* Change authentication response to avoid bruteforcing

* Add TODO item as a comment for changing the response for security purposes
2017-07-26 15:33:16 +08:00
..
2017-06-28 13:43:28 +08:00
2017-06-28 13:43:28 +08:00
2017-06-28 13:43:28 +08:00
2017-05-02 15:35:59 +02:00
2017-06-18 08:30:04 +08:00