summaryrefslogtreecommitdiff
path: root/django
diff options
context:
space:
mode:
authorAndrew Pinkham <code@andrewsforge.com>2017-04-25 15:26:58 -0400
committerTim Graham <timograham@gmail.com>2017-06-21 09:22:15 -0400
commita96b981d84367fd41b1df40adf3ac9ca71a741dd (patch)
tree3349d324683d69d18fce2ac6e5260e73853ba1a1 /django
parentb1cbbe926789bcfc2e118c7d7c7a0f30fab5248a (diff)
Fixed #28127 -- Allowed UserCreationForm's password validation to check all user fields.
Diffstat (limited to 'django')
-rw-r--r--django/contrib/auth/forms.py13
1 files changed, 11 insertions, 2 deletions
diff --git a/django/contrib/auth/forms.py b/django/contrib/auth/forms.py
index 1d6d5e2743..a5de5bf650 100644
--- a/django/contrib/auth/forms.py
+++ b/django/contrib/auth/forms.py
@@ -100,10 +100,19 @@ class UserCreationForm(forms.ModelForm):
self.error_messages['password_mismatch'],
code='password_mismatch',
)
- self.instance.username = self.cleaned_data.get('username')
- password_validation.validate_password(self.cleaned_data.get('password2'), self.instance)
return password2
+ def _post_clean(self):
+ super()._post_clean()
+ # Validate the password after self.instance is updated with form data
+ # by super().
+ password = self.cleaned_data.get('password2')
+ if password:
+ try:
+ password_validation.validate_password(password, self.instance)
+ except forms.ValidationError as error:
+ self.add_error('password2', error)
+
def save(self, commit=True):
user = super().save(commit=False)
user.set_password(self.cleaned_data["password1"])