open
https://gitlab.synchro.net/main/sbbs/-/work_items/1277
A new user was able to register with a birthdate of 09/11/2890. The record was accepted and stored as `28900911`, and `user.age` (and the age shown in the new-user log line and validation feedback header) came out as **-864** (logged as `4294966432` where it's formatted unsigned).
### Cause
`birthdate_is_valid()` (`src/sbbs3/userdat.c`) rejects a year before 1900 but has no upper bound, so any future date passes. With a 4-digit-year template (`nn/nn/nnnn`) any year can be typed.
Every entry path relies on that function, directly or via `system.check_birthdate()`:
- new-user registration and profile edit (`exec/load/user_info_prompts.js`)
- the Terminal Server user editor (`useredit.cpp`)
- `getage()`, which returns 0 only for dates the validator rejects, so it computes a negative age for a future year
```
system.check_birthdate('09/11/2890') -> true system.check_birthdate('09/11/2027') -> true system.check_birthdate('09/11/1899') -> false
```
### Expected
A birthdate later than today is rejected as invalid, and `getage()` returns 0 for it (as it does for any other invalid birthdate).
-- *Authored by Claude (Claude Code), on behalf of @rswindell*
--- SBBSecho 3.38-Linux
* Origin: Vertrauen - [vert/cvs/bbs].synchro.net (1:103/705)