Skip to content

[17.0][FIX] password_security: do not swallow the sign-up refusal - #1008

Closed
artemShelest wants to merge 1 commit into
OCA:17.0from
artemShelest:17.0-fix-password_security-signup-notfound
Closed

artemShelest wants to merge 1 commit into
OCA:17.0from
artemShelest:17.0-fix-password_security-signup-notfound

Conversation

@artemShelest

@artemShelest artemShelest commented Sep 15, 2026

Copy link
Copy Markdown

Withdrawn by the author. Nothing to review here.

web_auth_signup wraps the parent in `except Exception`, which catches the
NotFound the core controller raises when sign-up is disabled and re-renders
the sign-up form for it. A database with invitation-only sign-up therefore
answers 200 at /web/signup with a working-looking form on it. Nothing is
actually open — the POST is refused and res.users.signup() still raises
"Signup is not allowed for uninvited users" — but the page reads exactly
like the failure, so anyone checking by eye reads it backwards.

Re-raise werkzeug's HTTP exceptions instead. The broad catch below it stays:
it is what turns the raw ValueError from _create_user_from_template
("Signup: no name or partner given for new user") into a rendered form, which
test_06_web_auth_signup_invalid_render covers.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01ExBrmpp4Ea4H94FYroUVrN
@artemShelest
artemShelest deleted the 17.0-fix-password_security-signup-notfound branch September 15, 2026 18:18
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

mod:password_security Module password_security series:17.0

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants