fix: disallow usage of default password (#3284)

This commit is contained in:
Dag 2023-03-06 20:43:44 +01:00 committed by GitHub
parent f0e5ef0fc5
commit a01c1f6ab0
No known key found for this signature in database
GPG key ID: 4AEE18F83AFDEB23
3 changed files with 10 additions and 3 deletions

View file

@ -14,6 +14,13 @@
final class AuthenticationMiddleware
{
public function __construct()
{
if (Configuration::getConfig('authentication', 'password') === '') {
throw new \Exception('The authentication password cannot be the empty string');
}
}
public function __invoke(): void
{
$user = $_SERVER['PHP_AUTH_USER'] ?? null;