|
9 | 9 | namespace OCA\GlobalSiteSelector\Controller; |
10 | 10 |
|
11 | 11 | use OC\Authentication\Token\IProvider; |
| 12 | +use OC\User\DisabledUserException; |
12 | 13 | use OCA\GlobalSiteSelector\AppInfo\Application; |
13 | 14 | use OCA\GlobalSiteSelector\Exceptions\LocalFederatedShareException; |
14 | 15 | use OCA\GlobalSiteSelector\Exceptions\MasterUrlException; |
@@ -63,6 +64,7 @@ public function __construct( |
63 | 64 | private readonly IUserManager $userManager, |
64 | 65 | private readonly UserBackend $userBackend, |
65 | 66 | private readonly ISession $session, |
| 67 | + private readonly Slave $slave, |
66 | 68 | private readonly SlaveService $slaveService, |
67 | 69 | private readonly GlobalScaleService $globalScaleService, |
68 | 70 | private readonly GlobalShareService $globalShareService, |
@@ -159,6 +161,9 @@ public function autoLogin(string $jwt): RedirectResponse { |
159 | 161 | if (!($user instanceof IUser)) { |
160 | 162 | throw new \InvalidArgumentException('User is not valid'); |
161 | 163 | } |
| 164 | + if (!$user->isEnabled()) { |
| 165 | + throw new DisabledUserException('Account disabled'); |
| 166 | + } |
162 | 167 | $user->updateLastLoginTimestamp(); |
163 | 168 |
|
164 | 169 | $this->session->set('globalScale.userData', $options); |
@@ -191,6 +196,12 @@ public function autoLogin(string $jwt): RedirectResponse { |
191 | 196 | $response = new RedirectResponse($masterUrl); |
192 | 197 | $response->throttle(); |
193 | 198 | return $response; |
| 199 | + } catch (DisabledUserException $e) { |
| 200 | + // user is disabled, remove from lookup server |
| 201 | + $params = ['uid' => $uid]; |
| 202 | + $this->slave->preDeleteUser($params); |
| 203 | + $this->slave->deleteUser($params); |
| 204 | + return new RedirectResponse($masterUrl); |
194 | 205 | } catch (\Exception $e) { |
195 | 206 | $this->logger->warning('issue during login process', ['exception' => $e]); |
196 | 207 | $response = new RedirectResponse($masterUrl); |
|
0 commit comments