- Issue created by @eloivaque
- Assigned to arunkumark
- Status changed to Needs review
almost 2 years ago 4:48pm 7 February 2023 - Status changed to RTBC
almost 2 years ago 4:52pm 7 February 2023 - 🇮🇳India arunkumark Coimbatore
Reviewed the patch with the Drupal 9 core version. The patch prevents the page break for the Invalid user logout. Attached screenshot on after the patch is applied.
Moving the issue to RTBC.
- Status changed to Needs work
6 months ago 4:54pm 12 May 2024 - 🇨🇦Canada mandclu
Thanks for the work to date. That said, the proposed patch explicitly checks for characters within parentheses, which IMHO isn't really validating that the specified user exists. I would suggest that the code should:
1. Check only for digits within the parentheses
2. Actually try to load the user with the provided uidif both of those are, I would consider the specified user to be properly validated.
- Issue was unassigned.