From ba91d6a3da1ffaf1d68854add205967c36875629 Mon Sep 17 00:00:00 2001 From: Ryan Boren Date: Tue, 7 Mar 2006 05:59:28 +0000 Subject: [PATCH] Sanitize user_login in register form git-svn-id: https://develop.svn.wordpress.org/trunk@3629 602fd350-edb4-49c9-b593-d223f7449a82 --- wp-register.php | 13 ++++++++----- 1 file changed, 8 insertions(+), 5 deletions(-) diff --git a/wp-register.php b/wp-register.php index e0c6c04365..1a4dc78e2f 100644 --- a/wp-register.php +++ b/wp-register.php @@ -25,10 +25,13 @@ case 'register': $errors['user_email'] = __('ERROR: Please type your e-mail address.'); } else if (!is_email($user_email)) { $errors['user_email'] = __('ERROR: The email address isn’t correct.'); + $user_email = ''; } - if ( ! validate_username($user_login) ) + if ( ! validate_username($user_login) ) { $errors['user_login'] = __('ERROR: This username is invalid. Please enter a valid username.'); + $user_login = ''; + } if ( username_exists( $user_login ) ) $errors['user_login'] = __('ERROR: This username is already registered, please choose another one.'); @@ -65,9 +68,9 @@ case 'register':

-

$user_login") ?>
+

" . wp_specialchars($user_login) . "") ?>
' . __('emailed to you') . '') ?>
- $user_email") ?>

+ " . wp_specialchars($user_email) . "") ?>

@@ -108,8 +111,8 @@ default:

-

-


+

+