# ...snip...
# untaint parameters
for( keys %params )
{
# !!!TODO!!! check 'ref' line for subtle bugs
( display_message( $messages{error} ) && exit )
unless ref($valid_params{$_}) eq 'Regexp';
if( $params{$_} =~ /$valid_params{$_}/ )
{
$params{$_} = $1;
}
else
{
display_message( $messages{error} ) && exit;
}
}
####
my $userfile = get_userfile( $config, $params{username} );
##
##
sub get_userfile
{
my ( $config, $username ) = ( shift, shift );
# add only this line: still tainted
# ( $config->{ users } ) = ( $config->{ users } =~ /^(.+)$/ );
# add only this line: untainted
# ( $username ) = ( $username =~ /^(.+)$/ );
$config->{ users } . $username;
}