dmeese / MathWorld

Team Bunny Slippers Math World Web Application
0 stars 1 forks source link

I can register user even though the userid is not consistent #11

Closed ravthan closed 11 years ago

ravthan commented 11 years ago

The website doesn't give me an error message when I type "!@#$%^&()" and ")(&^%$#@!" as userid, which i have to type twice during registration. It seems to be fine. Not only that, I can login using the first userid I typed, i.e. "!@#$%^&*()", ravi.

CKinWoodstock commented 11 years ago

Team, do we want to limit user ids to alphanumerics? I don't see a problem with allowing the above characters in an id (so long as they pass stripify), but they are unconventional.

ravthan commented 11 years ago

What I forgot to mention was, when I insert a control character in between the above metnioned userids, it gets accepted too, ravi.

CKinWoodstock commented 11 years ago

Accepted as bug. Will limit userid to standard alphanumeric characters (including underscore)