mirror of
https://github.com/coder/coder.git
synced 2026-09-24 15:04:27 +08:00
fix: don't allow "new" or "create" as url-friendly names (#13596)
This commit is contained in:
@@ -46,7 +46,7 @@ func init() {
|
||||
valid := NameValid(str)
|
||||
return valid == nil
|
||||
}
|
||||
for _, tag := range []string{"username", "organization_name", "template_name", "workspace_name", "oauth2_app_name"} {
|
||||
for _, tag := range []string{"username", "organization_name", "template_name", "group_name", "workspace_name", "oauth2_app_name"} {
|
||||
err := Validate.RegisterValidation(tag, nameValidator)
|
||||
if err != nil {
|
||||
panic(err)
|
||||
@@ -62,7 +62,7 @@ func init() {
|
||||
valid := DisplayNameValid(str)
|
||||
return valid == nil
|
||||
}
|
||||
for _, displayNameTag := range []string{"organization_display_name", "template_display_name"} {
|
||||
for _, displayNameTag := range []string{"organization_display_name", "template_display_name", "group_display_name"} {
|
||||
err := Validate.RegisterValidation(displayNameTag, displayNameValidator)
|
||||
if err != nil {
|
||||
panic(err)
|
||||
|
||||
@@ -46,6 +46,10 @@ func NameValid(str string) error {
|
||||
if len(str) < 1 {
|
||||
return xerrors.New("must be >= 1 character")
|
||||
}
|
||||
// Avoid conflicts with routes like /templates/new and /groups/create.
|
||||
if str == "new" || str == "create" {
|
||||
return xerrors.Errorf("cannot use %q as a name", str)
|
||||
}
|
||||
matched := UsernameValidRegex.MatchString(str)
|
||||
if !matched {
|
||||
return xerrors.New("must be alphanumeric with hyphens")
|
||||
|
||||
Reference in New Issue
Block a user