jbb01 / QED

MIT License
11 stars 2 forks source link

Passwords are not correctly encoded #40

Closed jbb01 closed 1 month ago

jbb01 commented 1 year ago

In QEDLogin username and password are simply concatenate with aString::format call and not properly encoded. Users with an ampersand in their password can therefore not log in.

jbb01 commented 11 months ago

As a temporary workaround one could encode their password themselves, i.e. replace all occurances of "&" with "%26", "%" with "%25" and so on.