Quote from: vhollo at Aug 04, 2008, 02:06 PMIn this processor file I can’t find validity check for the username. Is that correct? Are every characters acceptable?
Actually the processor file can do it with
if (!$rs = mysql_query($sql)) {
webAlert("An error occurred while attempting to retrieve all users with username $newusername.");
exit;
}
Trying this if (!$rs =...) kinda thing on the web side doesn’t catch and breaks with a MODx error report.
What should I do to check if the username craps without explicitly filter out bad chars?
The original (v1.30) snippet filtered these chars:
$illegals = array(’.’ , ’,’ , ’/’ , ’\\’ , ’`’ , ’;’ , ’[’ , ’]’ , ’-’, "’", ’*’, ’&’, ’^’, ’%’, ’$’, ’#’, ’@’, ’!’, ’~’, ’+’, ’(’, ’)’, ’|’, ’{’, ’}’, ’<’, ’>’, ’?’, ’:’, ’"’, ’=’);
I know that not all, but which ones of these are necessary, and what are missing? I actually found only these two characters to be harmful: \ and ’
Or can I catch the error on the web side like the processor does on the backend?