validation.AttributionRE (pkg/forms/validation/email.go) is [a-z_]+ without anchors, and SignupForm.Save uses MatchString to decide whether to keep the submitted attribution or replace it with unknown. Any value containing a single lowercase letter passes, so arbitrary text (up to 100 characters) is stored as the attribution, for example Test <b>x</b> or 123 anything.
Expected: only simple tokens such as index_page are kept (^[a-z_]+$), and anything else becomes unknown.
Low impact while signups are disabled. Pinned by a skipped test, TestAttributionRE_RejectsFreeText, in pkg/forms/validation/email_test.go.
validation.AttributionRE(pkg/forms/validation/email.go) is[a-z_]+without anchors, andSignupForm.SaveusesMatchStringto decide whether to keep the submitted attribution or replace it withunknown. Any value containing a single lowercase letter passes, so arbitrary text (up to 100 characters) is stored as the attribution, for exampleTest <b>x</b>or123 anything.Expected: only simple tokens such as
index_pageare kept (^[a-z_]+$), and anything else becomesunknown.Low impact while signups are disabled. Pinned by a skipped test,
TestAttributionRE_RejectsFreeText, inpkg/forms/validation/email_test.go.