Commit 65e1a3b0 authored by Nicolás Alvarez's avatar Nicolás Alvarez
Browse files

Fix addition to default group when username contains a dash

I didn't notice that usernames could have a dash when I originally wrote
this.
parent f76d2917
......@@ -379,7 +379,7 @@ class User extends SLdapModel
if( $this->groups->count() == 0 ) {
// This should never fail since uid is validated elsewhere,
// but I want to be *very* sure I'm not introducing a shell injection bug.
if (preg_match('/^[a-z]+$/', $this->uid)) {
if (preg_match('/^[a-z-]+$/', $this->uid)) {
shell_exec("./protected/yiic usermanagement addDefaultGroup --username={$this->uid} >/dev/null &");
} else {
$this->addError("uid", "Internal error, username using invalid characters");
......
Supports Markdown
0% or .
You are about to add 0 people to the discussion. Proceed with caution.
Finish editing this message first!
Please register or to comment