diff --git a/flask_security/confirmable.py b/flask_security/confirmable.py index ca13d71..bfdcd2d 100644 --- a/flask_security/confirmable.py +++ b/flask_security/confirmable.py @@ -58,7 +58,7 @@ def generate_confirmation_token(user): def requires_confirmation(user): """Returns `True` if the user requires confirmation.""" - return _security.confirmable and user.confirmed_at == None + return _security.confirmable and not _security.login_without_confirmation and user.confirmed_at == None def confirm_email_token_status(token): diff --git a/flask_security/core.py b/flask_security/core.py index f36e6e9..fbccc15 100644 --- a/flask_security/core.py +++ b/flask_security/core.py @@ -114,6 +114,7 @@ _default_messages = { 'EMAIL_NOT_PROVIDED': ('Email not provided', 'error'), 'INVALID_EMAIL_ADDRESS': ('Invalid email address', 'error'), 'PASSWORD_NOT_PROVIDED': ('Password not provided', 'error'), + 'PASSWORD_NOT_SET': ('No password is set for this user', 'error'), 'PASSWORD_INVALID_LENGTH': ('Password must be at least 6 characters', 'error'), 'USER_DOES_NOT_EXIST': ('Specified user does not exist', 'error'), 'INVALID_PASSWORD': ('Invalid password', 'error'), diff --git a/flask_security/forms.py b/flask_security/forms.py index 8b509e9..2b62ab2 100644 --- a/flask_security/forms.py +++ b/flask_security/forms.py @@ -228,6 +228,9 @@ class LoginForm(Form, NextFormMixin): if self.user is None: self.email.errors.append(get_message('USER_DOES_NOT_EXIST')[0]) return False + if not self.user.password: + self.password.errors.append(get_message('PASSWORD_NOT_SET')[0]) + return False if not verify_and_update_password(self.password.data, self.user): self.password.errors.append(get_message('INVALID_PASSWORD')[0]) return False