From 1d520423a9858d6d5f4d8a1e8c97acb796d67063 Mon Sep 17 00:00:00 2001 From: Christian Boltz Date: Thu, 1 May 2014 22:52:47 +0000 Subject: [PATCH] login.php, users/login.php: - trim() $fUsername - MySQL thinks "foo" == "foo " (and therefore allows login as "foo@example.com " - but later we'll get funny "undefined index" problems in PFAHander->view()) when an admin wants to change the password git-svn-id: https://svn.code.sf.net/p/postfixadmin/code/trunk@1665 a1433add-5e2c-0410-b055-b7f2511e0802 --- login.php | 2 +- users/login.php | 2 +- 2 files changed, 2 insertions(+), 2 deletions(-) diff --git a/login.php b/login.php index 2b0bb0d4..4d83ae0d 100644 --- a/login.php +++ b/login.php @@ -38,7 +38,7 @@ if($CONF['configured'] !== true) { if ($_SERVER['REQUEST_METHOD'] == "POST") { $lang = safepost('lang'); - $fUsername = safepost('fUsername'); + $fUsername = trim(safepost('fUsername')); $fPassword = safepost('fPassword'); if ( $lang != check_language(0) ) { # only set cookie if language selection was changed diff --git a/users/login.php b/users/login.php index 6ed99a3e..e697c95f 100644 --- a/users/login.php +++ b/users/login.php @@ -34,7 +34,7 @@ require_once("../common.php"); if ($_SERVER['REQUEST_METHOD'] == "POST") { $lang = safepost('lang'); - $fUsername = safepost('fUsername'); + $fUsername = trim(safepost('fUsername')); $fPassword = safepost('fPassword'); if ( $lang != check_language(0) ) { # only set cookie if language selection was changed