Skip to content
This repository was archived by the owner on Oct 10, 2024. It is now read-only.
This repository was archived by the owner on Oct 10, 2024. It is now read-only.

mysql server has gone away --> Token Validation succeeds #1

@martinhaase

Description

@martinhaase

Hi Jordan,
the TokenValidator is calling getTokenList, which succeeds also if the PI server has no connection to its database, as piConnection:getTokenList does not call checkAPISuccess. This means, in case of an unstable database, that 2FA is bypassed. We see this as an security issue, the plugin should not let the flow succeed in this case.
Regards,
Martin

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions