- Affected version
- 2.3.2
Users sometimes mess up the registration form by pasting their email address as username and successfully submitting the form.
As the username is (by default) limited to 25 characters the pasted email address is truncated and the username might end up as smth. like
Users usually do not want their email address to be public so this causes somewhat unnecessary support workload to change their username.
Suggested Mitigation
Disallow usernames that are identical with the beginning of the email address.
As the username is (by default) limited to 25 characters the pasted email address is truncated and the username might end up as smth. like
firstname.lastname@gmail.
which is not considered a valid email address and thus not blocked.Users usually do not want their email address to be public so this causes somewhat unnecessary support workload to change their username.
Suggested Mitigation
Disallow usernames that are identical with the beginning of the email address.