Skip to content

Commit 1dc15e1

Browse files
author
Joan He
committed
MAGETWO-51123: No proper input validation in security section
1 parent 0dfd558 commit 1dc15e1

File tree

1 file changed

+4
-4
lines changed

1 file changed

+4
-4
lines changed

app/code/Magento/Security/etc/adminhtml/system.xml

Lines changed: 4 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -21,15 +21,15 @@
2121
<field id="max_number_password_reset_requests" translate="label comment" type="text" sortOrder="7" showInDefault="1" showInWebsite="1" showInStore="1">
2222
<label>Max Number of Password Reset Requests</label>
2323
<comment>Limit the number of password reset request per hour. Use 0 to disable.</comment>
24-
<validate>required-entry validate-zero-or-greater</validate>
24+
<validate>required-entry validate-zero-or-greater validate-digits</validate>
2525
<depends>
2626
<field id="password_reset_protection_type" separator="," negative="1">0</field>
2727
</depends>
2828
</field>
2929
<field id="min_time_between_password_reset_requests" translate="label comment" type="text" sortOrder="8" showInDefault="1" showInWebsite="1" showInStore="1">
3030
<label>Min Time Between Password Reset Requests</label>
3131
<comment>Delay in minutes between password reset requests. Use 0 to disable.</comment>
32-
<validate>required-entry validate-zero-or-greater</validate>
32+
<validate>required-entry validate-zero-or-greater validate-digits</validate>
3333
<depends>
3434
<field id="password_reset_protection_type" separator="," negative="1">0</field>
3535
</depends>
@@ -45,15 +45,15 @@
4545
<field id="max_number_password_reset_requests" translate="label comment" type="text" sortOrder="6" showInDefault="1" showInWebsite="1" showInStore="1">
4646
<label>Max Number of Password Reset Requests</label>
4747
<comment>Limit the number of password reset request per hour. Use 0 to disable.</comment>
48-
<validate>required-entry validate-zero-or-greater</validate>
48+
<validate>required-entry validate-zero-or-greater validate-digits</validate>
4949
<depends>
5050
<field id="password_reset_protection_type" separator="," negative="1">0</field>
5151
</depends>
5252
</field>
5353
<field id="min_time_between_password_reset_requests" translate="label comment" type="text" sortOrder="7" showInDefault="1" showInWebsite="1" showInStore="1">
5454
<label>Min Time Between Password Reset Requests</label>
5555
<comment>Delay in minutes between password reset requests. Use 0 to disable.</comment>
56-
<validate>required-entry validate-zero-or-greater</validate>
56+
<validate>required-entry validate-zero-or-greater validate-digits</validate>
5757
<depends>
5858
<field id="password_reset_protection_type" separator="," negative="1">0</field>
5959
</depends>

0 commit comments

Comments
 (0)