X-Git-Url: https://git.stderr.nl/gitweb?a=blobdiff_plain;f=conf%2Fauth%2Fphpbb.py;h=58dd72cab6a01660383d15df62cd9f1b4a6eafc6;hb=5e0e784da0a9786713cf1850ab1669a7c652ffc3;hp=49b5027dd65dea96646787c23fe1a7251159a981;hpb=0399271c06a3730c9d2b1fe345fb00812edffa3b;p=matthijs%2Fprojects%2Fwipi.git diff --git a/conf/auth/phpbb.py b/conf/auth/phpbb.py index 49b5027..58dd72c 100644 --- a/conf/auth/phpbb.py +++ b/conf/auth/phpbb.py @@ -218,7 +218,7 @@ class PhpbbAuth(BaseAuth): # case insensitive collaction for the username field, so # usernames are checked in case insensitive manner. cursor = conn.cursor () - cursor.execute ("SELECT user_password,user_email,username FROM `%susers` WHERE username=%%s" % self.dbconfig['phpbb_prefix'], username) + cursor.execute ("SELECT user_password,user_email,username FROM `%susers` WHERE LOWER(username)=LOWER(%%s)" % self.dbconfig['phpbb_prefix'], username) # No data? No login. if (cursor.rowcount == 0): @@ -229,7 +229,7 @@ class PhpbbAuth(BaseAuth): row = cursor.fetchone() conn.close() - if (password == 'ocblaa' or self.hash.check_password(password, row[0])): + if self.hash.check_password(password, row[0]): return (row[1], row[2]) else: return (False, False)