API: return 401 for invalid session

This commit is contained in:
Nihad Abbasov 2012-09-20 08:38:08 -07:00
parent 3dd940d4cb
commit b08d33f6a9
2 changed files with 4 additions and 5 deletions

View file

@ -8,14 +8,13 @@ module Gitlab
post "/session" do
resource = User.find_for_database_authentication(email: params[:email])
return forbidden! unless resource
return unauthorized! unless resource
if resource.valid_password?(params[:password])
present resource, with: Entities::UserLogin
else
forbidden!
unauthorized!
end
end
end
end