Closed
Description
Unrelated to this PR but it's a regex??? That's a surprise
Does this open up an attack where someone passes
[email protected]
and I go registermailqexample.com
and can pass the check?
Originally posted by @znewman01 in #1869 (comment)
I don't think this is necessarily a problem except users shouldn't be surprised by it or do the wrong thing by default. So maybe: make it loudly warn, or make regex behavior configurable? Or support globs instead?
Metadata
Assignees
Labels
No labels
Activity