fix: properly allow date-based passwords for galleries
Mirror to GitHub / mirror (push) Successful in 23s
Test and Lint / backend-test (push) Successful in 1m6s
continuous-integration/drone/push Build is passing
Test and Lint / frontend-test (push) Successful in 2m9s
Version and Release / version-bump (push) Successful in 31s
Version and Release / trigger-drone (push) Successful in 3s
Mirror to GitHub / mirror (push) Successful in 23s
Test and Lint / backend-test (push) Successful in 1m6s
continuous-integration/drone/push Build is passing
Test and Lint / frontend-test (push) Successful in 2m9s
Version and Release / version-bump (push) Successful in 31s
Version and Release / trigger-drone (push) Successful in 3s
- Added skipStrengthCheck option to bypass zxcvbn analysis for gallery passwords - Added explicit date pattern matching for formats like "04.07.2025" - Date passwords (DD.MM.YYYY, DD/MM/YYYY, DD-MM-YYYY) are now automatically accepted - Gallery passwords skip all strength requirements but maintain 6 character minimum - Fixes production issue where date passwords were rejected by zxcvbn 🤖 Generated with [Claude Code](https://claude.ai/code) Co-Authored-By: Claude <[email protected]>
This commit is contained in:
@@ -78,6 +78,16 @@ function validatePassword(password, options = {}) {
|
|||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
|
// Skip zxcvbn check if explicitly disabled (for gallery passwords)
|
||||||
|
if (options.skipStrengthCheck) {
|
||||||
|
return {
|
||||||
|
valid: errors.length === 0,
|
||||||
|
errors,
|
||||||
|
score: 2, // Default moderate score for gallery passwords
|
||||||
|
feedback: {}
|
||||||
|
};
|
||||||
|
}
|
||||||
|
|
||||||
// Use zxcvbn for strength analysis
|
// Use zxcvbn for strength analysis
|
||||||
const strength = zxcvbn(password);
|
const strength = zxcvbn(password);
|
||||||
|
|
||||||
@@ -121,19 +131,32 @@ function validatePasswordInContext(password, context, userData = {}) {
|
|||||||
requireNumbers: false, // Numbers are optional
|
requireNumbers: false, // Numbers are optional
|
||||||
requireSpecialChars: false, // Special chars are optional
|
requireSpecialChars: false, // Special chars are optional
|
||||||
preventCommonPasswords: true, // Still prevent common passwords
|
preventCommonPasswords: true, // Still prevent common passwords
|
||||||
minStrengthScore: 0 // Accept any score for galleries
|
minStrengthScore: 0, // Accept any score for galleries
|
||||||
|
skipStrengthCheck: true // Skip zxcvbn strength analysis for galleries
|
||||||
};
|
};
|
||||||
|
|
||||||
// Base validation with gallery-specific options
|
// Base validation with gallery-specific options
|
||||||
const result = validatePassword(password, galleryOptions);
|
const result = validatePassword(password, galleryOptions);
|
||||||
|
|
||||||
|
// Override validation for common date formats
|
||||||
|
// Allow passwords like "04.07.2025", "04/07/2025", "04-07-2025"
|
||||||
|
const datePattern = /^\d{1,2}[.\/-]\d{1,2}[.\/-]\d{4}$/;
|
||||||
|
if (datePattern.test(password)) {
|
||||||
|
// Date format is valid for gallery passwords
|
||||||
|
return {
|
||||||
|
valid: true,
|
||||||
|
errors: [],
|
||||||
|
score: 2,
|
||||||
|
feedback: {}
|
||||||
|
};
|
||||||
|
}
|
||||||
|
|
||||||
// Additional gallery-specific checks
|
// Additional gallery-specific checks
|
||||||
if (password.length < 6) {
|
if (password.length < 6) {
|
||||||
result.valid = false;
|
result.valid = false;
|
||||||
result.errors = ['Password must be at least 6 characters long'];
|
result.errors = ['Password must be at least 6 characters long'];
|
||||||
}
|
}
|
||||||
|
|
||||||
// Allow date-based passwords like "04.07.2025"
|
|
||||||
// Check if it's too simple (e.g., just "123456")
|
// Check if it's too simple (e.g., just "123456")
|
||||||
if (/^\d{1,6}$/.test(password)) {
|
if (/^\d{1,6}$/.test(password)) {
|
||||||
result.valid = false;
|
result.valid = false;
|
||||||
|
|||||||
Reference in New Issue
Block a user