diff options
author | 3D-I <marktravai@gmail.com> | 2019-03-31 07:08:20 +0200 |
---|---|---|
committer | 3D-I <marktravai@gmail.com> | 2019-03-31 07:08:26 +0200 |
commit | dc80ffdb40472fa9344765162c9d21d57f270de0 (patch) | |
tree | 30397a98129bfa62b48417b5ef6d90cab8d798a4 /phpBB/includes/functions_user.php | |
parent | e6ac4daf64a0671f21166708045a74ae59f5f048 (diff) | |
download | forums-dc80ffdb40472fa9344765162c9d21d57f270de0.tar forums-dc80ffdb40472fa9344765162c9d21d57f270de0.tar.gz forums-dc80ffdb40472fa9344765162c9d21d57f270de0.tar.bz2 forums-dc80ffdb40472fa9344765162c9d21d57f270de0.tar.xz forums-dc80ffdb40472fa9344765162c9d21d57f270de0.zip |
[ticket/16004] Add check-in for Emojis in Username
PHPBB3-16004
Diffstat (limited to 'phpBB/includes/functions_user.php')
-rw-r--r-- | phpBB/includes/functions_user.php | 7 |
1 files changed, 7 insertions, 0 deletions
diff --git a/phpBB/includes/functions_user.php b/phpBB/includes/functions_user.php index d019b867fa..5789981429 100644 --- a/phpBB/includes/functions_user.php +++ b/phpBB/includes/functions_user.php @@ -1760,6 +1760,13 @@ function validate_username($username, $allowed_username = false) return 'USERNAME_TAKEN'; } + // Check for out-of-bounds characters that are currently + // not supported by utf8_bin in MySQL + if (preg_match('/[\x{10000}-\x{10FFFF}]/u', $username)) + { + return 'INVALID_EMOJIS_USERNAME'; + } + $sql = 'SELECT group_name FROM ' . GROUPS_TABLE . " WHERE LOWER(group_name) = '" . $db->sql_escape(utf8_strtolower($username)) . "'"; |