Authenticate tell the difference between a verified account.

Description

On the authenticate REST API endpoint, if username and/or password are incorrect it's ok to make a generic error, but if the correct username and password are used, but the user has not been activated yet, send back a specific error message so it is clear why they cannot authenticate.

Status

Assignee

Brad Wood

Reporter

Brad Wood

Labels

None

Components

Fix versions

Priority

Major
Configure