fix: portable error reporting for PAM (#11296)

Linux PAM reports "Authentication Failure"
OpenPAM reports "authentication error"

This resulted in forgejo reporting error 500 on FreeBSD when pam
authentication failed.

Add a sentinel error to make this portable: ErrInvalidCredentials

Signed-off-by: Baptiste Daroussin <bapt@FreeBSD.org>
Reviewed-on: https://codeberg.org/forgejo/forgejo/pulls/11296
Reviewed-by: Gusted <gusted@noreply.codeberg.org>
Co-authored-by: Baptiste Daroussin <bapt@FreeBSD.org>
Co-committed-by: Baptiste Daroussin <bapt@FreeBSD.org>
This commit is contained in:
Baptiste Daroussin
2026-02-16 05:57:01 +01:00
committed by Gusted
parent 9767cebc42
commit 9762f9ea20
4 changed files with 18 additions and 2 deletions
@@ -5,6 +5,7 @@ package pam
import (
"context"
"errors"
"fmt"
"strings"
@@ -23,7 +24,7 @@ import (
func (source *Source) Authenticate(ctx context.Context, user *user_model.User, userName, password string) (*user_model.User, error) {
pamLogin, err := pam.Auth(source.ServiceName, userName, password)
if err != nil {
if strings.Contains(err.Error(), "Authentication failure") {
if errors.Is(err, pam.ErrInvalidCredentials) {
return nil, user_model.ErrUserNotExist{Name: userName}
}
return nil, err