Meneame icon indicating copy to clipboard operation
Meneame copied to clipboard

Certain username patterns can't be accessed

Open wileeam opened this issue 9 years ago • 0 comments

Users whose username ends in .php are considered a file to be interpreted by the web server.

See the author of this comment: https://www.meneame.net/story/800-euros-ingeniero-superior-pongame-kilo-cuarto/c071#c-71 whose username is 'dario.php' Upon clicking his username, the response from the server is that the file wasn't found (hence Apache rules are firing before the application's code). It turns that changing the username to anything ending in .php is also allowed (at least the part that verifies for the existence of such username). I didn't complete the change on my account for obvious reasons of being locked out :)

This is not an issue in the source code (it is unusual to have such type of append in the username though) but rather on the configuration on the server side. Rewriting rules should help solve the issue or the harsh one of disallowing these endings in usernames?

wileeam avatar Nov 28 '15 09:11 wileeam