|
15 | 15 | HTTP_AUTH_MAX_LOGIN_POST_LENGTH = 500 # We ignore every posted content exceeding that length to prevent false positives |
16 | 16 | HTTP_AUTH_POTENTIAL_USERNAMES = ['log', 'login', 'wpname', 'ahd_username', 'unickname', 'nickname', 'user', 'user_name', |
17 | 17 | 'alias', 'pseudo', 'email', 'username', '_username', 'userid', 'form_loginname', |
18 | | - 'loginname', 'login_id', 'loginid', 'session_key', 'sessionkey', 'pop_login', 'uid', |
19 | | - 'id', 'user_id', 'screename', 'uname', 'ulogin', 'acctname', 'account', 'member', |
| 18 | + 'loginname', 'login_id', 'loginid', 'session_key', 'sessionkey', 'pop_login', |
| 19 | + 'user_id', 'screename', 'uname', 'ulogin', 'acctname', 'account', 'member', |
20 | 20 | 'mailaddress', 'membername', 'login_username', 'login_email', 'loginusername', |
21 | | - 'loginemail', 'uin', 'sign-in', 'j_username'] |
| 21 | + 'loginemail', 'sign-in', 'j_username'] |
22 | 22 |
|
23 | 23 | HTTP_AUTH_POTENTIAL_PASSWORDS = ['ahd_password', 'pass', 'password', '_password', 'passwd', 'session_password', |
24 | | - 'sessionpassword', 'login_password', 'loginpassword', 'form_pw', 'pw', 'userpassword', |
25 | | - 'pwd', 'upassword', 'login_password', 'passwort', 'passwrd', 'wppassword', 'upasswd', |
| 24 | + 'sessionpassword', 'login_password', 'loginpassword', 'form_pw', 'userpassword', |
| 25 | + 'upassword', 'login_password', 'passwort', 'passwrd', 'wppassword', 'upasswd', |
26 | 26 | 'j_password'] |
27 | 27 |
|
28 | 28 |
|
|
0 commit comments