reject usernames made only of dots

A username of "." or ".." passed validation, but browsers resolve those as path segments, so requests to /users/{username} never reached the API and the user could not be deleted or edited from the UI. User creation now rejects dot-only names in both the API and the create user dialog.
This commit is contained in:
Josh Hawkins
2026-10-09 23:50:37 -05:00
parent 7786da465f
commit ec9319853f
3 changed files with 35 additions and 2 deletions
@@ -80,7 +80,7 @@ export default function CreateUserDialog({
user: z
.string()
.min(1, t("users.dialog.form.usernameIsRequired"))
.regex(/^[A-Za-z0-9._]+$/, {
.regex(/^(?!\.+$)[A-Za-z0-9._]+$/, {
message: t("users.dialog.createUser.usernameOnlyInclude"),
}),
password: z