If spammers can abuse something, they gonna abuse it

  • Björn Tantau
    link
    fedilink
    395 months ago

    I mean, allowing arbitrary characters in the name is one thing. I think I would do that as well, as there are many weird names out there.

    But then actually parsing it out (or not escaping it properly), that’s the real sin.