From 8edc263237cd42cbecfe3dd53ff02d6632a07e64 Mon Sep 17 00:00:00 2001 From: Brian Wolff Date: Mon, 9 May 2016 03:51:01 -0400 Subject: [PATCH] [SECURITY] Canonicalize usernames before rate limiting logins Bug: T127114 Change-Id: I020cecf345c6bad4f461b70203f0bd29792de1f8 --- includes/specials/SpecialUserlogin.php | 6 ++++-- 1 file changed, 4 insertions(+), 2 deletions(-) diff --git a/includes/specials/SpecialUserlogin.php b/includes/specials/SpecialUserlogin.php index 9a2e194..735ef14 100644 --- a/includes/specials/SpecialUserlogin.php +++ b/includes/specials/SpecialUserlogin.php @@ -724,7 +724,8 @@ class LoginForm extends SpecialPage { */ public static function incLoginThrottle( $username ) { global $wgPasswordAttemptThrottle, $wgMemc, $wgRequest; - $username = trim( $username ); // sanity + $canUsername = User::getCanonicalName( $username, 'usable' ); + $username = $canUsername !== false ? $canUsername : $username; $throttleCount = 0; if ( is_array( $wgPasswordAttemptThrottle ) ) { @@ -752,7 +753,8 @@ class LoginForm extends SpecialPage { */ public static function clearLoginThrottle( $username ) { global $wgMemc, $wgRequest; - $username = trim( $username ); // sanity + $canUsername = User::getCanonicalName( $username, 'usable' ); + $username = $canUsername !== false ? $canUsername : $username; $throttleKey = wfMemcKey( 'password-throttle', $wgRequest->getIP(), md5( $username ) ); $wgMemc->delete( $throttleKey ); -- 2.0.1