Skip to content

Commit

Permalink
add a bit of user input sanitization
Browse files Browse the repository at this point in the history
  • Loading branch information
Petricpwnz committed Nov 19, 2018
1 parent 32b3145 commit 47b765b
Showing 1 changed file with 4 additions and 0 deletions.
4 changes: 4 additions & 0 deletions qai/qai_plugin.py
Original file line number Diff line number Diff line change
Expand Up @@ -363,6 +363,8 @@ def remind(self, mask, target, args):

global REMINDER_RECEIVERS, REMINDER_DB_ACTION_LOCK
player_name = args.get('<playername>')
if not self._is_a_nickname(player_name):
return 'Invalid nickname.'
try:
time_before_reminding = {
'seconds': int(args.get('<seconds>', 0) or 0),
Expand Down Expand Up @@ -428,6 +430,8 @@ def offline_message(self, mask, target, args):
%%offlinemessage <playername> WORDS ...
"""
player_name, message = args.get('<playername>'), " ".join(args.get('WORDS'))
if not self._is_a_nickname(player_name):
return 'Invalid nickname.'
if mask.nick == player_name:
self._taunt(mask.nick)
return
Expand Down

0 comments on commit 47b765b

Please sign in to comment.