From b80781017874e5bc30c25476d2cafc2f4f2a0b93 Mon Sep 17 00:00:00 2001 From: AulaEmpresaLKS <129507941+AulaEmpresaLKS@users.noreply.github.com> Date: Mon, 31 Mar 2025 11:39:00 +0200 Subject: [PATCH] Update Owner.java Signed-off-by: AulaEmpresaLKS <129507941+AulaEmpresaLKS@users.noreply.github.com> --- .../springframework/samples/petclinic/owner/Owner.java | 8 ++++++++ 1 file changed, 8 insertions(+) diff --git a/src/main/java/org/springframework/samples/petclinic/owner/Owner.java b/src/main/java/org/springframework/samples/petclinic/owner/Owner.java index 675b2140e..2b22ad3f2 100644 --- a/src/main/java/org/springframework/samples/petclinic/owner/Owner.java +++ b/src/main/java/org/springframework/samples/petclinic/owner/Owner.java @@ -170,6 +170,14 @@ public class Owner extends Person { Assert.notNull(pet, "Invalid Pet identifier!"); pet.addVisit(visit); + + (req: Request, res: Response, next: NextFunction) => { + verifyPreLoginChallenges(req) // vuln-code-snippet hide-line + models.sequelize.query('SELECT * FROM Users WHERE email = :email AND password = :password AND deletedAt IS NULL', { + replacements: { email: req.body.email || '', password: security.hash(req.body.password || '') }, + model: UserModel, + plain: true + }) } }