Update login fn to return 401 Unauthorized vs 403 Forbidden

This commit is contained in:
xbgmsharp
2023-10-04 16:39:40 +02:00
parent 0f08667d3f
commit 9c7301deac

View File

@@ -183,7 +183,10 @@ begin
-- check email and password
select auth.user_role(email, pass) into _role;
if _role is null then
raise invalid_password using message = 'invalid user or password';
-- HTTP/403
--raise invalid_password using message = 'invalid user or password';
-- HTTP/401
raise insufficient_privilege using message = 'invalid user or password';
end if;
-- Get app_jwt_secret