fix(auth): treat zxcvbn suggestions as advice, not blocking errors (#1247)

Stable twin of #1050. passwordValidation.js is byte-identical between the
branches, so this is the same change verbatim.

validatePassword() appended zxcvbn's feedback.suggestions to the errors
array unconditionally, and validity is errors.length === 0 — so any
password that merely earned a suggestion was rejected even when it
satisfied every configured rule. The effective policy was stricter than
the configured complexity level and invisible to the admin.

Co-authored-by: Paul Nothaft <[email protected]>
Co-authored-by: Peifu Mo <[email protected]>
This commit is contained in:
Paul Nothaft
2026-09-01 08:05:57 +02:00
committed by GitHub
co-authored by Paul Nothaft Peifu Mo
parent c05faa50d9
commit eebca9900b
18 changed files with 64 additions and 5 deletions
+8 -5
View File
@@ -94,11 +94,14 @@ function validatePassword(password, options = {}) {
// Check minimum strength score
if (strength.score < config.minStrengthScore) {
errors.push('Password is too weak. Please choose a stronger password');
}
// Add zxcvbn suggestions
if (strength.feedback.suggestions.length > 0) {
errors.push(...strength.feedback.suggestions);
// Surface zxcvbn's suggestions only alongside a real failure — they are
// advice, not requirements. A password that meets the configured policy
// must not be rejected just because zxcvbn has ideas for improving it
// (e.g. "Natasha2023" scores exactly minStrengthScore but always carries
// an "add another word" suggestion, which used to fail it).
if (strength.feedback.suggestions.length > 0) {
errors.push(...strength.feedback.suggestions);
}
}
return {