Delete password rather than simply clearing it

This commit is contained in:
Vinyl Darkscratch
2019-02-04 09:56:58 -08:00
parent 1457e12f70
commit 8852df7a7a
+2 -1
View File
@@ -2637,7 +2637,8 @@ class Auth(AuthAPI):
# invalid login
session.flash = specific_error if self.settings.login_specify_error else self.messages.invalid_login
callback(onfail, None)
request.post_vars['password'] = ""
if 'password' in request.post_vars:
del request.post_vars['password']
redirect(
self.url(args=request.args, get_vars=request.get_vars, post_vars=request.post_vars),
client_side=settings.client_side)