Commit 262ece0d by Seefs

fix: check oauthUser.Username length

parent 0427ddda
...@@ -240,9 +240,12 @@ func findOrCreateOAuthUser(c *gin.Context, provider oauth.Provider, oauthUser *o ...@@ -240,9 +240,12 @@ func findOrCreateOAuthUser(c *gin.Context, provider oauth.Provider, oauthUser *o
if oauthUser.Username != "" { if oauthUser.Username != "" {
if exists, err := model.CheckUserExistOrDeleted(oauthUser.Username, ""); err == nil && !exists { if exists, err := model.CheckUserExistOrDeleted(oauthUser.Username, ""); err == nil && !exists {
// 防止索引退化
if len(oauthUser.Username) <= model.UserNameMaxLength {
user.Username = oauthUser.Username user.Username = oauthUser.Username
} }
} }
}
if oauthUser.DisplayName != "" { if oauthUser.DisplayName != "" {
user.DisplayName = oauthUser.DisplayName user.DisplayName = oauthUser.DisplayName
......
...@@ -15,6 +15,8 @@ import ( ...@@ -15,6 +15,8 @@ import (
"gorm.io/gorm" "gorm.io/gorm"
) )
const UserNameMaxLength = 20
// User if you add sensitive fields, don't forget to clean them in setupLogin function. // User if you add sensitive fields, don't forget to clean them in setupLogin function.
// Otherwise, the sensitive information will be saved on local storage in plain text! // Otherwise, the sensitive information will be saved on local storage in plain text!
type User struct { type User struct {
......
Markdown is supported
0% or
You are about to add 0 people to the discussion. Proceed with caution.
Finish editing this message first!
Please register or sign in to comment