svn: /web/php-master/trunk/entry/ svn-account.php
| From: | Philip Olson | Date: | Sat, 19 Dec 2009 20:21:45 +0000 |
| Subject: | svn: /web/php-master/trunk/entry/ svn-account.php | ||
| Groups: | php.webmaster | ||
| Request: | Send a blank email to php-webmaster+get-6802@lists.php.net to get a copy of this message | ||
philip Sat, 19 Dec 2009 20:21:45 +0000
Revision: http://svn.php.net/viewvc?view=revision&revision=292340
Log:
Require usernames to be [a-z0-9_.-], and update the 'bad users' list
Changed paths:
U web/php-master/trunk/entry/svn-account.php
Modified: web/php-master/trunk/entry/svn-account.php
===================================================================
--- web/php-master/trunk/entry/svn-account.php 2009-12-19 20:14:16 UTC (rev 292339)
+++ web/php-master/trunk/entry/svn-account.php 2009-12-19 20:21:45 UTC (rev 292340)
@@ -44,9 +44,13 @@
# placed in qmail-smtpd's badmailfrom to block future emails.) some of these
# latter addresses were used as examples in the documentation at one point,
# which means they appear on all sorts of spam lists.
-if
(in_array($username,array('nse','roys','php','foo','group','core','webmaster','mysql','web','aardvark','zygote','jag','sites','er')))
+if
(in_array($username,array('nse','roys','php','foo','group','core','webmaster','web','aardvark','zygote','jag','sites','er','sqlite','cvs2svn')))
die("that username is not available");
+if (!preg_match('@^[a-z0-9_.-]+$@', $username)) {
+ die("that username is invalid, use alphanumeric characters, or more specifically:
[a-z0-9_.-]");
+}
+
@mysql_connect("localhost","nobody", "")
or die("failed to connect to database");
@mysql_select_db("phpmasterdb")