From 9f1e8177e780950694afd0d25b22fdb779fd948e Mon Sep 17 00:00:00 2001 From: milanio Date: Mon, 8 May 2017 17:40:03 +0100 Subject: [PATCH] Fix - attempt to login with incorrect password could delete password --- Lynicon/Membership/LightweightMembershipProvider.cs | 2 -- 1 file changed, 2 deletions(-) diff --git a/Lynicon/Membership/LightweightMembershipProvider.cs b/Lynicon/Membership/LightweightMembershipProvider.cs index c92ac2b..f10b6f5 100644 --- a/Lynicon/Membership/LightweightMembershipProvider.cs +++ b/Lynicon/Membership/LightweightMembershipProvider.cs @@ -488,10 +488,8 @@ protected internal virtual IUser ValidateUser(string username, string password, if (isInitial || EncryptPassword(password) == user.Password) return user; string pwd = user.Password; - user.Password = null; if (AlternateEncrypt != null && AlternateEncrypt(user, password).Contains(pwd)) { - user.Password = pwd; return user; }