From a73f32f7dc4ff48f7dded07b9205beb1e84362c1 Mon Sep 17 00:00:00 2001 From: Eugen Rochko Date: Mon, 28 Feb 2022 12:15:44 +0100 Subject: [PATCH] Fix being able to bypass e-mail restrictions --- app/models/user.rb | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/app/models/user.rb b/app/models/user.rb index a38362e575..9fcc54c3e7 100644 --- a/app/models/user.rb +++ b/app/models/user.rb @@ -86,11 +86,11 @@ class User < ApplicationRecord validates :invite_request, presence: true, on: :create, if: :invite_text_required? validates :locale, inclusion: I18n.available_locales.map(&:to_s), if: :locale? - validates_with BlacklistedEmailValidator, on: :create + validates_with BlacklistedEmailValidator, if: -> { !confirmed? } validates_with EmailMxValidator, if: :validate_email_dns? validates :agreement, acceptance: { allow_nil: false, accept: [true, 'true', '1'] }, on: :create - # Those are honeypot/antispam fields + # Honeypot/anti-spam fields attr_accessor :registration_form_time, :website, :confirm_password validates_with RegistrationFormTimeValidator, on: :create