mirror of
https://github.com/BradNut/example-sveltekit-email-password-webauthn
synced 2025-09-08 17:40:27 +00:00
fix 403 checks
This commit is contained in:
parent
f5b1b80f4c
commit
25c54572a7
4 changed files with 4 additions and 4 deletions
|
|
@ -24,7 +24,7 @@ export async function POST(event: RequestEvent) {
|
|||
status: 401
|
||||
});
|
||||
}
|
||||
if (!user.emailVerified || !user.registeredPasskey || session.twoFactorVerified) {
|
||||
if (!session.emailVerified || !user.registeredPasskey || session.twoFactorVerified) {
|
||||
return new Response("Forbidden", {
|
||||
status: 403
|
||||
});
|
||||
|
|
|
|||
|
|
@ -35,7 +35,7 @@ async function action(event: RequestEvent) {
|
|||
message: "Not authenticated"
|
||||
});
|
||||
}
|
||||
if (!user.emailVerified || !user.registered2FA || session.twoFactorVerified) {
|
||||
if (!session.emailVerified || !user.registered2FA || session.twoFactorVerified) {
|
||||
return fail(403, {
|
||||
message: "Forbidden"
|
||||
});
|
||||
|
|
|
|||
|
|
@ -24,7 +24,7 @@ export async function POST(event: RequestEvent) {
|
|||
status: 401
|
||||
});
|
||||
}
|
||||
if (!user.emailVerified || !user.registeredSecurityKey || session.twoFactorVerified) {
|
||||
if (!session.emailVerified || !user.registeredSecurityKey || session.twoFactorVerified) {
|
||||
return new Response("Forbidden", {
|
||||
status: 403
|
||||
});
|
||||
|
|
|
|||
|
|
@ -40,7 +40,7 @@ async function action(event: RequestEvent) {
|
|||
message: "Not authenticated"
|
||||
});
|
||||
}
|
||||
if (!user.emailVerified || !user.registeredTOTP || session.twoFactorVerified) {
|
||||
if (!session.emailVerified || !user.registeredTOTP || session.twoFactorVerified) {
|
||||
return fail(403, {
|
||||
message: "Forbidden"
|
||||
});
|
||||
|
|
|
|||
Loading…
Reference in a new issue