SECURITY: Remove email validation check bypass

- Increase size of email column to varchar(513)
 - Give error message on signup when email is too large

Overall impact: Low, allows signups from blocked domains. Main risk is increased spam.
This commit is contained in:
Kane York
2015-07-13 13:40:52 -07:00
parent 4f103f7cc5
commit 2a897a8a6b
3 changed files with 13 additions and 0 deletions

View File

@ -0,0 +1,8 @@
class EnlargeUsersEmailField < ActiveRecord::Migration
def up
change_column :users, :email, :string, :limit => 513
end
def down
change_column :users, :email, :string, :limit => 128
end
end