]> sipb.mit.edu Git - ikiwiki.git/blobdiff - IkiWiki/Plugin/openid.pm
further sanitize nickname characters
[ikiwiki.git] / IkiWiki / Plugin / openid.pm
index f4ba8db189c8bcb6e0c3592c55fee760430c73c8..4727577f342587bc1e99fdc77c8afb1a42bdb91e 100644 (file)
@@ -187,12 +187,17 @@ sub auth ($$) {
                                        $vident->signed_extension_fields('http://openid.net/srv/ax/1.0'),
                                );
                        }
+                       my $nickname;
                        foreach my $ext (@extensions) {
                                foreach my $field (qw{value.email email}) {
                                        if (exists $ext->{$field} &&
                                            defined $ext->{$field} &&
                                            length $ext->{$field}) {
                                                $session->param(email => $ext->{$field});
+                                               if (! defined $nickname &&
+                                                   $ext->{$field}=~/(.+)@.+/) {
+                                                       $nickname = $1;
+                                               }
                                                last;
                                        }
                                }
@@ -200,11 +205,16 @@ sub auth ($$) {
                                        if (exists $ext->{$field} &&
                                            defined $ext->{$field} &&
                                            length $ext->{$field}) {
-                                               $session->param(username => $ext->{$field});
+                                               $nickname=$ext->{$field};
                                                last;
                                        }
                                }
                        }
+                       if (defined $nickname) {
+                               $nickname=~s/\s+/_/g;
+                               $nickname=~s/[^-_0-9[:alnum:]]+//g;
+                               $session->param(nickname => $nickname);
+                       }
                }
                else {
                        error("OpenID failure: ".$csr->err);