-
2007-04-25
furun
The registration of the user name is case sensitive. This is a security hole because it is possible to create users like "andi" "Andi" "ANDI" "andI"... and so one. User names should be case insensitive unique.
And it is bad for users witch register as "Name" and try too login as "name", and down't understand why there login was disallowed.
Is there a workaround?
-
2007-04-25
furun
+
The user name and password should not be changed in no kind way (no to-lower, no characters to "_"...). instead a error message should be viewed.
-
2007-05-14
gb
Usernames (logins) are case insensitive in devel revision, only andi is allowed. Using anything else when this user exists and you try to create Andi for example leads to an error which is the right behaviour. Bad username error message is useless: all usernames are lowercase.
Haven't tested with release 2006-11-06
-
2007-05-24
furun
This is True.
(My wiki down't change the case, maybe becomes of the CamelCase Option (not tested)...)
But it is not better if the names are not changed at all, and Dokuwiki check internal everything in lowercase?
And if you use this 'autopasswd' option and change Spaces to "_", the user down't see this changements and think that the system block the registration. (this is hapen in my wiki because a user try too register as "Name Name", without re-mailing a Password.)
-
2008-10-11
foosel
Usernames have been case insensitive for a while now and are handled equally to page ids