I think many of us are aware of the cautionary tale of Robert Drop Tables.
Well, it appears that FD also don't always sanitize their inputs.
I discovered today that someone on my frield list, whose name starts with <- does not have their name displayed on the contacts screen. Works on the chat screen, so presume someone got the code right there, but obviously running different code for the contacts screen.... naughty naughty FD! Why are you not reusing the same code for displaying CMDR names on all UI elements? Tut tut! You're just making extra work for yourselves.
So, who wants to send a ticket to FD support to change their CMDR name to ); DROP TABLE players?

Well, it appears that FD also don't always sanitize their inputs.
I discovered today that someone on my frield list, whose name starts with <- does not have their name displayed on the contacts screen. Works on the chat screen, so presume someone got the code right there, but obviously running different code for the contacts screen.... naughty naughty FD! Why are you not reusing the same code for displaying CMDR names on all UI elements? Tut tut! You're just making extra work for yourselves.
So, who wants to send a ticket to FD support to change their CMDR name to ); DROP TABLE players?
Last edited: