{% extends "base.html" %} {% block title %}{{ user.display_name or user.username }}'s Profile - {{ config.BBS_NAME }}{% endblock %} {% block content %}
@{{ user.username }}
{% endif %} {% if online %} Online {% else %} Offline {% endif %} {% if user.is_admin %}{{ user.location }}
{% endif %} {% if field_config.website and user.website %} {# Security fix (templates audit): user.website is a free-text profile field with no scheme validation on save (web/profile.py). Rendering it straight into href= let a user set it to a javascript: URI, which would execute in any other visitor's session when they clicked the "website" link on that profile page -- the same class of bug as the gemini/RSS javascript: URI fix elsewhere in this app. Only link-ify it when it's actually an http(s) URL. #} {% set _site = user.website.strip() %}{% if _site.lower().startswith('http://') or _site.lower().startswith('https://') %} {{ _site }} {% else %} {{ _site }} {% endif %}
{% endif %} {% if field_config.show_email and user.show_email %}{{ user.email }}
{% endif %}Joined {{ user.created_at|eastern('%Y-%m-%d') }}
{% if user.last_login %}Last login {{ user.last_login|eastern('%Y-%m-%d') }}
{% endif %} {% for cf in custom_fields_list %} {% set val = custom_values.get(cf.id) %} {% if val %}{% if cf.field_type == 'url' %} {# Same javascript: URI risk as user.website above -- custom "url" fields are also free text with no scheme validation on save. #} {% set _val = (val|string).strip() %} {{ cf.label }}: {% if _val.lower().startswith('http://') or _val.lower().startswith('https://') %} {{ _val }} {% else %} {{ _val }} {% endif %} {% else %} {{ cf.label }}: {{ val }} {% endif %}
{% endif %} {% endfor %}Posts: {{ stats.total_posts }}
Replies: {{ stats.total_replies }}
Member for: {{ stats.account_age }} days
{{ user.bio }}
No posts yet.
{% endif %}