Skip to content
Open
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
13 changes: 12 additions & 1 deletion api/controller/auth.js
Original file line number Diff line number Diff line change
Expand Up @@ -2,7 +2,8 @@ var jwt = require('jwt-simple'),
users = require('./users.js'),
mongo = require('mongodb'),
otplib = require('otplib'),
common = require('../../dashboard/helper/common');
common = require('../../dashboard/helper/common'),
regexValidate = require('../../dashboard/helper/regexValidate');

var security;
var secret;
Expand Down Expand Up @@ -249,6 +250,16 @@ exports.verify2FA = function(req, res) {
exports.signup = function(req, res) {

var user = JSON.parse(req.body.user);

//validate username - only alphanumeric characters and spaces allowed
if (user.name && !regexValidate("user").test(user.name)) {
res.status(401).send({
'error': 'Invalid Username',
'code': 34
});
return;
}

if(user.beforeSignup) {
validateUsername(user.name, function(user) {
if(user == false) {
Expand Down
21 changes: 20 additions & 1 deletion api/controller/users.js
Original file line number Diff line number Diff line change
Expand Up @@ -2,7 +2,8 @@

var mongo = require('mongodb'),
journal = require('./journal'),
otplib = require('otplib');
otplib = require('otplib'),
regexValidate = require('../../dashboard/helper/regexValidate');

var db;

Expand Down Expand Up @@ -677,6 +678,15 @@ exports.addUser = function(req, res) {
//parse user details
var user = JSON.parse(req.body.user);

//validate username - only alphanumeric characters and spaces allowed
if (user.name && !regexValidate("user").test(user.name)) {
res.status(401).send({
'error': 'Invalid Username',
'code': 34
});
return;
}

//add timestamp & language
user.created_time = +new Date();
user.timestamp = +new Date();
Expand Down Expand Up @@ -841,6 +851,15 @@ exports.updateUser = function(req, res) {
var user = JSON.parse(req.body.user);
delete user.role; // Disable role change

//validate username - only alphanumeric characters and spaces allowed
if (user.name && !regexValidate("user").test(user.name)) {
res.status(401).send({
'error': 'Invalid Username',
'code': 34
});
return;
}

//do not update name if already exist
if (typeof user.name !== 'undefined') {
//check for unique user name validation
Expand Down