fix: properly evaluate AURREMEMBER cookie

Whenever the AURREMEMBER cookie was defined, regardless of its value,
"remember_me" is always set to True

The get method of a dict returns a string,
converting a value of str "False" into a bool -> True

We have to check AURREMEMBERs value instead.

Signed-off-by: moson-mo <mo-son@mailbox.org>
This commit is contained in:
moson-mo 2023-05-25 13:23:37 +02:00
parent 5fe375bdc3
commit 2eacc84cd0
No known key found for this signature in database
GPG key ID: 4A4760AB4EE15296
3 changed files with 3 additions and 5 deletions

View file

@ -131,7 +131,7 @@ def password(
user.update_password(P)
if user == request.user:
remember_me = request.cookies.get("AURREMEMBER", False)
remember_me = request.cookies.get("AURREMEMBER") == "True"
# If the target user is the request user, login with
# the updated password to update the Session record.