fix(auth): treat zxcvbn suggestions as advice, not blocking errors (#1247)
Stable twin of #1050. passwordValidation.js is byte-identical between the branches, so this is the same change verbatim. validatePassword() appended zxcvbn's feedback.suggestions to the errors array unconditionally, and validity is errors.length === 0 — so any password that merely earned a suggestion was rejected even when it satisfied every configured rule. The effective policy was stricter than the configured complexity level and invisible to the admin. Co-authored-by: Paul Nothaft <[email protected]> Co-authored-by: Peifu Mo <[email protected]>
This commit is contained in:
co-authored by
Paul Nothaft
Peifu Mo
parent
c05faa50d9
commit
eebca9900b
@@ -94,11 +94,14 @@ function validatePassword(password, options = {}) {
|
||||
// Check minimum strength score
|
||||
if (strength.score < config.minStrengthScore) {
|
||||
errors.push('Password is too weak. Please choose a stronger password');
|
||||
}
|
||||
|
||||
// Add zxcvbn suggestions
|
||||
if (strength.feedback.suggestions.length > 0) {
|
||||
errors.push(...strength.feedback.suggestions);
|
||||
// Surface zxcvbn's suggestions only alongside a real failure — they are
|
||||
// advice, not requirements. A password that meets the configured policy
|
||||
// must not be rejected just because zxcvbn has ideas for improving it
|
||||
// (e.g. "Natasha2023" scores exactly minStrengthScore but always carries
|
||||
// an "add another word" suggestion, which used to fail it).
|
||||
if (strength.feedback.suggestions.length > 0) {
|
||||
errors.push(...strength.feedback.suggestions);
|
||||
}
|
||||
}
|
||||
|
||||
return {
|
||||
|
||||
Reference in New Issue
Block a user