Skip to content

Signup attribution regex is unanchored and accepts any input #148

Description

@can3p

validation.AttributionRE (pkg/forms/validation/email.go) is [a-z_]+ without anchors, and SignupForm.Save uses MatchString to decide whether to keep the submitted attribution or replace it with unknown. Any value containing a single lowercase letter passes, so arbitrary text (up to 100 characters) is stored as the attribution, for example Test <b>x</b> or 123 anything.

Expected: only simple tokens such as index_page are kept (^[a-z_]+$), and anything else becomes unknown.

Low impact while signups are disabled. Pinned by a skipped test, TestAttributionRE_RejectsFreeText, in pkg/forms/validation/email_test.go.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    bugSomething isn't working

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions