I just have realised that forbidden usernames are case sensitive. So if you deny "moderator" in the backend, the user still can create an account as "MODERATOR". There seem to be some weird combinations possible. Some of them allow registration, some not:
These would work:
Moderator
mOderator
moDerator
ModeratoR
ModerAtoR
THis would not work:
modErator
modeRator
moderAtor
moderaTor
moderaTOR
Just to name a few. I would say this is a bug. A forbidden username schould be not case sensitive at all, meaning that any combination of case and non case letters in that word would not be allowed.
A user would not really be able to tell if moderator or MODERATOR or moderAtoR would be a legit moderator. Therfor this should be changed.
moderatOr
moderatoR
Post edited by: KatoKalin, at: 2010/07/26 21:38
Post edited by: krileon, at: 2010/07/27 21:41