From 011dc5870f2aa06f90f5067a2cabf634ea659719 Mon Sep 17 00:00:00 2001 From: Bob Mottram <bob@freedombone.net> Date: Sun, 19 Aug 2018 13:34:06 +0100 Subject: [PATCH] Don't need to check password --- webadmin/newuser.php | 14 ++++++-------- 1 file changed, 6 insertions(+), 8 deletions(-) diff --git a/webadmin/newuser.php b/webadmin/newuser.php index c1f103101..ada29ec8b 100755 --- a/webadmin/newuser.php +++ b/webadmin/newuser.php @@ -13,15 +13,13 @@ if (isset($_POST['submitnewuser'])) { else { // Don't rely on php PRNG $newpassword = exec("openssl rand -base64 32 | tr -dc A-Za-z0-9 | head -c 10 ; echo -n ''"); - if (preg_match('/^[a-z\d_]{8,32}$/i', $newpassword)) { - $new_user_file = fopen(".new_user.txt", "w") or die("Unable to write to new_user file"); - fwrite($new_user_file, $username.",".$newpassword); - fclose($new_user_file); + $new_user_file = fopen(".new_user.txt", "w") or die("Unable to write to new_user file"); + fwrite($new_user_file, $username.",".$newpassword); + fclose($new_user_file); - exec('cp new_user_confirm_template.html new_user_confirm.html'); - exec('sed -i "s|NEWPASSWORD|'.$newpassword.'|g" new_user_confirm.html'); - $output_filename = "new_user_confirm.html"; - } + exec('cp new_user_confirm_template.html new_user_confirm.html'); + exec('sed -i "s|NEWPASSWORD|'.$newpassword.'|g" new_user_confirm.html'); + $output_filename = "new_user_confirm.html"; } } -- GitLab