diff options
author | Eugen Rochko <eugen@zeonfederated.com> | 2022-03-30 14:45:52 +0200 |
---|---|---|
committer | GitHub <noreply@github.com> | 2022-03-30 14:45:52 +0200 |
commit | 5554ff2a1d6f451d63d03f4eb0a740d8c91455de (patch) | |
tree | a59a5b9dd6745eed64ef43a8a10c69aa56295556 /app | |
parent | 607ce67e05885108fbcbe0e3c170718a5586044e (diff) |
Fix being able to bypass e-mail restrictions (#17909)
Diffstat (limited to 'app')
-rw-r--r-- | app/models/user.rb | 4 |
1 files changed, 2 insertions, 2 deletions
diff --git a/app/models/user.rb b/app/models/user.rb index f2d9c49eb..e25c0ddb0 100644 --- a/app/models/user.rb +++ b/app/models/user.rb @@ -91,11 +91,11 @@ class User < ApplicationRecord validates :invite_request, presence: true, on: :create, if: :invite_text_required? validates :locale, inclusion: I18n.available_locales.map(&:to_s), if: :locale? - validates_with BlacklistedEmailValidator, on: :create + validates_with BlacklistedEmailValidator, if: -> { !confirmed? } validates_with EmailMxValidator, if: :validate_email_dns? validates :agreement, acceptance: { allow_nil: false, accept: [true, 'true', '1'] }, on: :create - # Those are honeypot/antispam fields + # Honeypot/anti-spam fields attr_accessor :registration_form_time, :website, :confirm_password validates_with RegistrationFormTimeValidator, on: :create |