Len Padilla wrote:
I recently discovered, after a careless user cut and pasted a name with a "^M" character in it, that there is no validation of the $name value of domain records.
I've modified functions.php to include a validation routing, which insists that the name field of the record contain only ".", "-", 0-9, a-z characters.
Following is a diff. I don't use the update-data.sh script (I use
sql2data) so it might be a good idea to include some sanity checking
there too, in case the DB contains illegal characters.
What is sql2data ? Custom script ?
Regards,
Len
-- --------------------------- Jason 'XenoPhage' Frisvold Engine / Technology Programmer [EMAIL PROTECTED] RedHat Certified - RHCE # 803004140609871 MySQL Pro Certified - ID# 207171862 MySQL Core Certified - ID# 205982910 --------------------------- "Something mysterious is formed, born in the silent void. Waiting alone and unmoving, it is at once still and yet in constant motion. It is the source of all programs. I do not know its name, so I will call it the Tao of Programming."
