Call to warden.authenticate! in resource_owner_from_credentials would make the request redirect to sign-in path, which is a bad response for apps. Now bad credentials just return nil, which leads to HTTP 401 from Doorkeeper. Also, accounts with enabled 2FA cannot be logged into this way. |
||
|---|---|---|
| .. | ||
| environments | ||
| initializers | ||
| locales | ||
| webpack | ||
| application.rb | ||
| boot.rb | ||
| brakeman.ignore | ||
| database.yml | ||
| deploy.rb | ||
| environment.rb | ||
| i18n-tasks.yml | ||
| navigation.rb | ||
| puma.rb | ||
| routes.rb | ||
| secrets.yml | ||
| settings.yml | ||
| sidekiq.yml | ||
| themes.yml | ||
| webpacker.yml | ||