<?xml version="1.0" encoding="UTF-8"?>
<commit>
  <added type="array"/>
  <modified type="array">
    <modified>
      <diff>@@ -74,6 +74,8 @@ class User &lt; ActiveRecord::Base
   
   # Returns the user that matches provided login and password, or nil
   def self.try_to_login(login, password)
+    # Make sure no one can sign in with an empty password
+    return nil if password.to_s.empty?
     user = find(:first, :conditions =&gt; [&quot;login=?&quot;, login])
     if user
       # user is already in local database</diff>
      <filename>app/models/user.rb</filename>
    </modified>
  </modified>
  <removed type="array"/>
  <parents type="array">
    <parent>
      <id>abaeecbaa9539e2497a34b7391799a81c3d0b29b</id>
    </parent>
  </parents>
  <author>
    <name>Jean-Philippe Lang</name>
    <email>jp_lang@yahoo.fr</email>
  </author>
  <url>http://github.com/edavis10/redmine/commit/a677817003fc065a3a6362c429ffe1a611067e49</url>
  <id>a677817003fc065a3a6362c429ffe1a611067e49</id>
  <committed-date>2008-03-12T10:57:46-07:00</committed-date>
  <authored-date>2008-03-12T10:57:46-07:00</authored-date>
  <message>Merged r1231 from trunk.

git-svn-id: http://redmine.rubyforge.org/svn/branches/0.6-stable@1232 e93f8b46-1217-0410-a6f0-8f06a7374b81</message>
  <tree>9ebeb713b2ef06c31733fdbb9cff55f963740f0c</tree>
  <committer>
    <name>Jean-Philippe Lang</name>
    <email>jp_lang@yahoo.fr</email>
  </committer>
</commit>
