Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Don't allow URLs in username #16633

Merged
merged 3 commits into from
Feb 5, 2025
Merged

Conversation

timkelty
Copy link
Contributor

@timkelty timkelty commented Feb 5, 2025

Description

Default email templates print user.friendlyName, and many email clients (like Gmail) will detect something that looks like a URL and automatically make it into a link.

Allowing a user with a username that looks like a URL could thus be seen as a potential phishing attack, as Craft will send an email that ends up looking like it has a direct link to a potentially malicious URL.

@timkelty timkelty closed this Feb 5, 2025
@timkelty timkelty force-pushed the feature/disallow-url-as-username branch from ab8444c to 22f7c04 Compare February 5, 2025 03:42
@timkelty timkelty reopened this Feb 5, 2025
@timkelty timkelty changed the base branch from 5.x to 4.x February 5, 2025 03:45
@brandonkelly brandonkelly merged commit bb22806 into 4.x Feb 5, 2025
@brandonkelly brandonkelly deleted the feature/disallow-url-as-username branch February 5, 2025 20:18
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

3 participants