Skip site navigation (1)Skip section navigation (2)
Date:      Fri, 18 Aug 2017 18:08:54 -0700
From:      "Ngie Cooper (yaneurabeya)" <yaneurabeya@gmail.com>
To:        Ed Maste <emaste@freebsd.org>
Cc:        src-committers <src-committers@freebsd.org>, svn-src-all@freebsd.org, svn-src-head@freebsd.org
Subject:   Re: svn commit: r322678 - in head/usr.sbin/pw: . tests
Message-ID:  <CEE799EF-356D-46F8-BD04-640A4A33EC79@gmail.com>
In-Reply-To: <201708190032.v7J0WQAa017551@repo.freebsd.org>
References:  <201708190032.v7J0WQAa017551@repo.freebsd.org>

next in thread | previous in thread | raw e-mail | index | archive | help

--Apple-Mail=_22802188-9797-4792-A343-4BD1D2E4FDF4
Content-Transfer-Encoding: 7bit
Content-Type: text/plain;
	charset=us-ascii


> On Aug 18, 2017, at 17:32, Ed Maste <emaste@freebsd.org> wrote:
> 
> Author: emaste
> Date: Sat Aug 19 00:32:26 2017
> New Revision: 322678
> URL: https://svnweb.freebsd.org/changeset/base/322678
> 
> Log:
>  pw useradd: Validate the user name before creating the entry
> 
>  Previouly it was possible to create users with spaces in the name with:
>  pw useradd -u 1234 -g 1234 -n 'test user'
> 
>  The "-g 1234" is relevant, without it the name was already rejected
>  as expected:
> 
>  [fk@test ~]$ sudo pw useradd -u 1234 -n 'test user'
>  pw: invalid character ` ' at position 4 in userid/group name
> 
>  Bug unintentionally found with a salt config without explicit name entry:
> 
>  test user:
>    user.present:
>      - uid: 1234
>      - gid: 1234
>      - fullname: Test user
>      - shell: /usr/local/bin/bash
>      - home: /home/test
>      - groups:
>        - wheel
>        - salt
> 
>  "Luckily" salt modules rarely bother with input validation either ...
> 
>  PR:		221416
>  Submitted by:	Fabian Keil
>  Obtained from:	ElectroBSD
>  MFC after:	1 week
> 
> Modified:
>  head/usr.sbin/pw/pw_user.c
>  head/usr.sbin/pw/tests/pw_useradd_test.sh

Usernames with passwords are permitted in some cases, e.g., AD.
Thanks,
-Ngie

--Apple-Mail=_22802188-9797-4792-A343-4BD1D2E4FDF4
Content-Transfer-Encoding: 7bit
Content-Disposition: attachment;
	filename=signature.asc
Content-Type: application/pgp-signature;
	name=signature.asc
Content-Description: Message signed with OpenPGP using GPGMail

-----BEGIN PGP SIGNATURE-----
Comment: GPGTools - https://gpgtools.org

iQIcBAEBCgAGBQJZl4+nAAoJEPWDqSZpMIYVGY0P/0M/T4jiP5+n1Cmqcw4qTJDD
SzzAKN4yQxttQrhLYEuACOvWKOwexyBO307+zCluN2Xm0zkMdFY/iUbjr6Z3uQtD
HZMcLvp40l1uyQtjXI4Xr3B86ElnYD5PFP0M3h/mjGZ6alG+dzcFUvzu5AItWN4E
IaTa2JsGhQoE5u4b00818fO3RnoKRKic8AvJcEfkNTDdZ4hcdluOAWDlyw3sleXy
JxoROMcCakkFkHSWcOmTGXw6ud1z4u5oDXWLzzLi+K57JwroATrRDHpzWcaJCxLG
NKAvbLvCdBhDEWzfdAnEaEEgtQ9J7By2Au2jZNOqrKKgnwP8XwFd3wgYAgN5A2wF
xetdTcE1+Qd0c75AE4++2RKWXYFHqTZLv4K4lv59GR9pX8IQgRWtGOHMWltr/bCj
Jn9lmXUYqpBNmPjOyBdBTiMwZ0kfvR1axvFcnUnszwC0+qqGrp82eCw7g0RqT4EF
vCwiRoREFNTSNS2pfEhXOWx6Mz+VHt3P1M9nbGaVOeXNyZRaK75uR8ltMGnn5KJq
yItVQ2llg050ijpAqoPHdkvf+sPRz38Rrwf1y0jdmua9dtRELzZFCNocczgaZcUp
SFG4167v15b9tcTUxtkm724Gh22/lIofdgJqdzstiUfICU4SEa6shPqi+G3t1XPa
IVwQtbe68RYVEnZW8zvE
=Q4jO
-----END PGP SIGNATURE-----

--Apple-Mail=_22802188-9797-4792-A343-4BD1D2E4FDF4--



Want to link to this message? Use this URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?CEE799EF-356D-46F8-BD04-640A4A33EC79>