Changeset 2293


Ignore:
Timestamp:
Apr 6, 2009, 10:13:53 PM (15 years ago)
Author:
broder
Message:

Fix a potential quota hole from cross-realm Hesiod entries.

File:
1 edited

Legend:

Unmodified
Added
Removed
  • trunk/packages/invirt-web/code/validation.py

    r2141 r2293  
    242242    if owner is None:
    243243        raise InvalidInput('owner', owner, "Owner must be specified")
     244    if '@' in owner:
     245        raise InvalidInput('owner', owner, "No cross-realm Hesiod lockers allowed")
    244246    try:
    245247        if user not in cache_acls.expandLocker(owner):
Note: See TracChangeset for help on using the changeset viewer.