From 128ae44a0d0af81cfdabdcc930efbd396f179a07 Mon Sep 17 00:00:00 2001 From: Adam Moussa <166072409+amoussa1229@users.noreply.github.com> Date: Thu, 16 Apr 2026 16:33:09 -0400 Subject: [PATCH] Fix login null check order and strengthen password reset code - Reorder null check: check user != null before accessing user.IsDeleted - Increase password reset code from 4 digits to 6 digits (10K to 1M combinations) --- .../Controllers/AuthenticationController.cs | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/Api.SeaHavenIndustries/Controllers/AuthenticationController.cs b/Api.SeaHavenIndustries/Controllers/AuthenticationController.cs index a3e0b95..346cde0 100644 --- a/Api.SeaHavenIndustries/Controllers/AuthenticationController.cs +++ b/Api.SeaHavenIndustries/Controllers/AuthenticationController.cs @@ -35,7 +35,7 @@ namespace Api.SeaHavenIndustries.Controllers public async Task Login([FromBody] LoginModel model) { var user = await _userManager.FindByNameAsync(model.Username ?? ""); - if (user.IsDeleted != true && user != null && await _userManager.CheckPasswordAsync(user, model.Password ?? "")) + if (user != null && user.IsDeleted != true && await _userManager.CheckPasswordAsync(user, model.Password ?? "")) { // Standard login without 2FA var userRoles = await _userManager.GetRolesAsync(user); @@ -214,7 +214,7 @@ namespace Api.SeaHavenIndustries.Controllers private Random _random = new Random(); private string GenerateRandomNo() { - return _random.Next(0, 9999).ToString("D4"); + return _random.Next(0, 999999).ToString("D6"); } #endregion }