actually disallow @ in display name
This commit is contained in:
@@ -404,7 +404,7 @@ def settings_form(username):
|
|||||||
else:
|
else:
|
||||||
rendered_sig = ''
|
rendered_sig = ''
|
||||||
session['subscribe_by_default'] = request.form.get('subscribe_by_default', default='off') == 'on'
|
session['subscribe_by_default'] = request.form.get('subscribe_by_default', default='off') == 'on'
|
||||||
display_name = request.form.get('display_name', default='')
|
display_name = request.form.get('display_name', default='').replace('@', '_')
|
||||||
if not validate_display_name(display_name):
|
if not validate_display_name(display_name):
|
||||||
flash('Invalid display name.', InfoboxKind.ERROR)
|
flash('Invalid display name.', InfoboxKind.ERROR)
|
||||||
return redirect('.settings', username=user.username)
|
return redirect('.settings', username=user.username)
|
||||||
|
|||||||
Reference in New Issue
Block a user