fix(api): allow bots with pending password changes (#39551)

Allow bot accounts to use the API when a legacy password-change flag is
set, since bots cannot complete the interactive password-change flow.
Preserve password-change enforcement for human accounts and restrictions
for inactive or prohibited accounts.

Fixes: https://github.com/go-gitea/gitea/issues/39542
Co-authored-by: wxiaoguang <wxiaoguang@gmail.com>
Co-authored-by: silverwind <me@silverwind.io>
This commit is contained in:
authored and GitHub committed 2026-10-03 17:22:07 +00:00
1 parent 516a4883fa
commit cca466caae
11 files changed
+129 -100

No files matched your search

-5
View File
@@ -211,11 +211,6 @@ func (ctx *Context) DoerNeedTwoFactorAuth() bool {
return ctx.Session.Get(session.KeyUserHasTwoFactorAuth) == false
}
// DoerIsImpersonated returns true if the current session is an admin impersonating the doer
func (ctx *Context) DoerIsImpersonated() bool {
return ctx.Session.Get(session.KeyImpersonatorData) != nil
}
// HasError returns true if error occurs in form validation.
// Attention: this function changes ctx.Data and ctx.Flash
// If HasError is called, then before Redirect, the error message should be stored by ctx.Flash.Error(ctx.GetErrMsg()) again.
+1 -1
View File
@@ -69,7 +69,7 @@ func (c TemplateContext) CurrentWebTheme() *webtheme.ThemeMetaInfo {
func (c TemplateContext) ImpersonatedUser() *user_model.User {
webCtx := GetWebContext(c)
if webCtx == nil || webCtx.Doer == nil || !webCtx.DoerIsImpersonated() {
if webCtx == nil || webCtx.Doer == nil || !IsDoerSessionImpersonated(webCtx.Session) {
return nil
}
return webCtx.Doer
+5
View File
@@ -9,6 +9,7 @@ import (
"strings"
user_model "gitea.dev/models/user"
"gitea.dev/modules/session"
)
// UserAssignmentWeb returns a middleware to handle context-user assignment for web routes
@@ -58,3 +59,7 @@ func userAssignment(ctx *Base, doer *user_model.User, errCb func(int, string)) (
}
return contextUser
}
func IsDoerSessionImpersonated(sess session.Store) bool {
return sess.Get(session.KeyImpersonatorData) != nil
}