API session login returns 400 bad request for expired / disabled user

mbodea20072 years ago

Hello,
the API session login returns 400 bad request for expired / disabled user...
Thx

Anton Tananaev2 years ago
  1. Why is that an issue?
  2. What's the payload?
mbodea20072 years ago

Hi,
It should return "Account has expired - SecurityException"
as in Disableable.java (last line):

throw new SecurityException(getClass().getSimpleName() + " has expired");

but it is returning
response status code: 400, "Bad request"
...
M

Anton Tananaev2 years ago

What about the second question?

mbodea20072 years ago

my bad: response is:
response: User is disabled - SecurityException (Disableable:36 < LoginService:99 < *:80 < SessionResource:137 < ...)
response.statusCode: 400

so it is OK. (it is changed from previous version I think - this is why I thought it's an error)
Sorry