Compare commits
8 Commits
| Author | SHA1 | Date | |
|---|---|---|---|
| 4af3cc2486 | |||
| 3632b936e9 | |||
| 66a6d4003a | |||
| bdf73c1f06 | |||
| f032743690 | |||
| a9902b95b4 | |||
| 9d1c0b672a | |||
| 727fd8bae8 |
Generated
+2
-2
@@ -1,12 +1,12 @@
|
|||||||
{
|
{
|
||||||
"name": "picpeak-backend",
|
"name": "picpeak-backend",
|
||||||
"version": "1.0.41",
|
"version": "1.0.45",
|
||||||
"lockfileVersion": 3,
|
"lockfileVersion": 3,
|
||||||
"requires": true,
|
"requires": true,
|
||||||
"packages": {
|
"packages": {
|
||||||
"": {
|
"": {
|
||||||
"name": "picpeak-backend",
|
"name": "picpeak-backend",
|
||||||
"version": "1.0.41",
|
"version": "1.0.45",
|
||||||
"dependencies": {
|
"dependencies": {
|
||||||
"adm-zip": "^0.5.16",
|
"adm-zip": "^0.5.16",
|
||||||
"archiver": "^5.3.1",
|
"archiver": "^5.3.1",
|
||||||
|
|||||||
@@ -1,6 +1,6 @@
|
|||||||
{
|
{
|
||||||
"name": "picpeak-backend",
|
"name": "picpeak-backend",
|
||||||
"version": "1.0.41",
|
"version": "1.0.45",
|
||||||
"description": "Backend for PicPeak event photo sharing platform",
|
"description": "Backend for PicPeak event photo sharing platform",
|
||||||
"main": "server.js",
|
"main": "server.js",
|
||||||
"scripts": {
|
"scripts": {
|
||||||
|
|||||||
@@ -66,7 +66,12 @@ router.post('/', adminAuth, [
|
|||||||
}
|
}
|
||||||
|
|
||||||
// Generate unique slug
|
// Generate unique slug
|
||||||
const baseSlug = `${event_type}-${event_name.toLowerCase().replace(/[^a-z0-9]/g, '-')}-${event_date}`;
|
const processedEventName = event_name
|
||||||
|
.toLowerCase()
|
||||||
|
.replace(/[^a-z0-9]/g, '-') // Replace non-alphanumeric with dash
|
||||||
|
.replace(/-+/g, '-') // Replace multiple dashes with single dash
|
||||||
|
.replace(/^-|-$/g, ''); // Remove leading/trailing dashes
|
||||||
|
const baseSlug = `${event_type}-${processedEventName}-${event_date}`;
|
||||||
let slug = baseSlug;
|
let slug = baseSlug;
|
||||||
let counter = 1;
|
let counter = 1;
|
||||||
|
|
||||||
|
|||||||
@@ -78,6 +78,16 @@ function validatePassword(password, options = {}) {
|
|||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
|
// Skip zxcvbn check if explicitly disabled (for gallery passwords)
|
||||||
|
if (options.skipStrengthCheck) {
|
||||||
|
return {
|
||||||
|
valid: errors.length === 0,
|
||||||
|
errors,
|
||||||
|
score: 2, // Default moderate score for gallery passwords
|
||||||
|
feedback: {}
|
||||||
|
};
|
||||||
|
}
|
||||||
|
|
||||||
// Use zxcvbn for strength analysis
|
// Use zxcvbn for strength analysis
|
||||||
const strength = zxcvbn(password);
|
const strength = zxcvbn(password);
|
||||||
|
|
||||||
@@ -111,7 +121,52 @@ function validatePassword(password, options = {}) {
|
|||||||
* @returns {Object} - Validation result
|
* @returns {Object} - Validation result
|
||||||
*/
|
*/
|
||||||
function validatePasswordInContext(password, context, userData = {}) {
|
function validatePasswordInContext(password, context, userData = {}) {
|
||||||
// Base validation
|
// For gallery context, use more lenient validation
|
||||||
|
if (context === 'gallery') {
|
||||||
|
// Gallery-specific validation options
|
||||||
|
const galleryOptions = {
|
||||||
|
minLength: 6, // Reduced minimum length
|
||||||
|
requireUppercase: false, // Don't require uppercase for galleries
|
||||||
|
requireLowercase: false, // Don't require lowercase for galleries
|
||||||
|
requireNumbers: false, // Numbers are optional
|
||||||
|
requireSpecialChars: false, // Special chars are optional
|
||||||
|
preventCommonPasswords: true, // Still prevent common passwords
|
||||||
|
minStrengthScore: 0, // Accept any score for galleries
|
||||||
|
skipStrengthCheck: true // Skip zxcvbn strength analysis for galleries
|
||||||
|
};
|
||||||
|
|
||||||
|
// Base validation with gallery-specific options
|
||||||
|
const result = validatePassword(password, galleryOptions);
|
||||||
|
|
||||||
|
// Override validation for common date formats
|
||||||
|
// Allow passwords like "04.07.2025", "04/07/2025", "04-07-2025"
|
||||||
|
const datePattern = /^\d{1,2}[.\/-]\d{1,2}[.\/-]\d{4}$/;
|
||||||
|
if (datePattern.test(password)) {
|
||||||
|
// Date format is valid for gallery passwords
|
||||||
|
return {
|
||||||
|
valid: true,
|
||||||
|
errors: [],
|
||||||
|
score: 2,
|
||||||
|
feedback: {}
|
||||||
|
};
|
||||||
|
}
|
||||||
|
|
||||||
|
// Additional gallery-specific checks
|
||||||
|
if (password.length < 6) {
|
||||||
|
result.valid = false;
|
||||||
|
result.errors = ['Password must be at least 6 characters long'];
|
||||||
|
}
|
||||||
|
|
||||||
|
// Check if it's too simple (e.g., just "123456")
|
||||||
|
if (/^\d{1,6}$/.test(password)) {
|
||||||
|
result.valid = false;
|
||||||
|
result.errors.push('Password cannot be just numbers. Consider using a date format like "04.07.2025"');
|
||||||
|
}
|
||||||
|
|
||||||
|
return result;
|
||||||
|
}
|
||||||
|
|
||||||
|
// Base validation for other contexts
|
||||||
const result = validatePassword(password);
|
const result = validatePassword(password);
|
||||||
|
|
||||||
// Context-specific validation
|
// Context-specific validation
|
||||||
@@ -136,16 +191,6 @@ function validatePasswordInContext(password, context, userData = {}) {
|
|||||||
result.errors.push('Password must not contain parts of your email');
|
result.errors.push('Password must not contain parts of your email');
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
} else if (context === 'gallery') {
|
|
||||||
// Gallery passwords can be more lenient for user convenience
|
|
||||||
// Allow passwords with score >= 1 (weak but acceptable)
|
|
||||||
if (result.score < 1) {
|
|
||||||
result.valid = false;
|
|
||||||
result.errors.push('Password is too simple. Please add more complexity');
|
|
||||||
}
|
|
||||||
|
|
||||||
// Don't check for event name in password - allow date-based passwords
|
|
||||||
// This allows passwords like "Sommer2025!" which users prefer
|
|
||||||
}
|
}
|
||||||
|
|
||||||
return result;
|
return result;
|
||||||
|
|||||||
Generated
+2
-2
@@ -1,12 +1,12 @@
|
|||||||
{
|
{
|
||||||
"name": "picpeak-frontend",
|
"name": "picpeak-frontend",
|
||||||
"version": "1.0.41",
|
"version": "1.0.45",
|
||||||
"lockfileVersion": 3,
|
"lockfileVersion": 3,
|
||||||
"requires": true,
|
"requires": true,
|
||||||
"packages": {
|
"packages": {
|
||||||
"": {
|
"": {
|
||||||
"name": "picpeak-frontend",
|
"name": "picpeak-frontend",
|
||||||
"version": "1.0.41",
|
"version": "1.0.45",
|
||||||
"dependencies": {
|
"dependencies": {
|
||||||
"@tanstack/react-query": "^5.0.0",
|
"@tanstack/react-query": "^5.0.0",
|
||||||
"@tiptap/extension-link": "^2.25.0",
|
"@tiptap/extension-link": "^2.25.0",
|
||||||
|
|||||||
@@ -1,7 +1,7 @@
|
|||||||
{
|
{
|
||||||
"name": "picpeak-frontend",
|
"name": "picpeak-frontend",
|
||||||
"private": true,
|
"private": true,
|
||||||
"version": "1.0.41",
|
"version": "1.0.45",
|
||||||
"type": "module",
|
"type": "module",
|
||||||
"scripts": {
|
"scripts": {
|
||||||
"dev": "vite",
|
"dev": "vite",
|
||||||
|
|||||||
@@ -204,6 +204,9 @@ export const CreateEventPage: React.FC = () => {
|
|||||||
newErrors.password = t('validation.passwordRequired');
|
newErrors.password = t('validation.passwordRequired');
|
||||||
} else if (formData.password.length < 6) {
|
} else if (formData.password.length < 6) {
|
||||||
newErrors.password = t('validation.passwordMinLength');
|
newErrors.password = t('validation.passwordMinLength');
|
||||||
|
} else if (/^\d{1,6}$/.test(formData.password)) {
|
||||||
|
// Prevent simple numeric passwords like "123456"
|
||||||
|
newErrors.password = t('validation.passwordTooSimple', 'Password cannot be just numbers. Consider using a date format like "04.07.2025"');
|
||||||
}
|
}
|
||||||
|
|
||||||
if (formData.password !== formData.confirm_password) {
|
if (formData.password !== formData.confirm_password) {
|
||||||
@@ -412,6 +415,7 @@ export const CreateEventPage: React.FC = () => {
|
|||||||
onChange={handleInputChange('password')}
|
onChange={handleInputChange('password')}
|
||||||
error={errors.password}
|
error={errors.password}
|
||||||
placeholder={t('events.enterPassword')}
|
placeholder={t('events.enterPassword')}
|
||||||
|
helperText={t('events.passwordHelperText', 'You can use dates like "04.07.2025" or any text with 6+ characters')}
|
||||||
leftIcon={<Lock className="w-5 h-5 text-neutral-400" />}
|
leftIcon={<Lock className="w-5 h-5 text-neutral-400" />}
|
||||||
className="pr-10"
|
className="pr-10"
|
||||||
/>
|
/>
|
||||||
|
|||||||
@@ -180,6 +180,9 @@ export const CreateEventPageEnhanced: React.FC = () => {
|
|||||||
newErrors.password = t('validation.passwordRequired');
|
newErrors.password = t('validation.passwordRequired');
|
||||||
} else if (formData.password.length < 6) {
|
} else if (formData.password.length < 6) {
|
||||||
newErrors.password = t('validation.passwordMinLength');
|
newErrors.password = t('validation.passwordMinLength');
|
||||||
|
} else if (/^\d{1,6}$/.test(formData.password)) {
|
||||||
|
// Prevent simple numeric passwords like "123456"
|
||||||
|
newErrors.password = t('validation.passwordTooSimple', 'Password cannot be just numbers. Consider using a date format like "04.07.2025"');
|
||||||
}
|
}
|
||||||
|
|
||||||
if (formData.password !== formData.confirm_password) {
|
if (formData.password !== formData.confirm_password) {
|
||||||
@@ -309,7 +312,6 @@ export const CreateEventPageEnhanced: React.FC = () => {
|
|||||||
value={formData.event_date}
|
value={formData.event_date}
|
||||||
onChange={handleInputChange('event_date')}
|
onChange={handleInputChange('event_date')}
|
||||||
error={errors.event_date}
|
error={errors.event_date}
|
||||||
min={format(new Date(), 'yyyy-MM-dd')}
|
|
||||||
leftIcon={<Calendar className="w-5 h-5" />}
|
leftIcon={<Calendar className="w-5 h-5" />}
|
||||||
/>
|
/>
|
||||||
</div>
|
</div>
|
||||||
@@ -454,6 +456,7 @@ export const CreateEventPageEnhanced: React.FC = () => {
|
|||||||
value={formData.password}
|
value={formData.password}
|
||||||
onChange={handleInputChange('password')}
|
onChange={handleInputChange('password')}
|
||||||
error={errors.password}
|
error={errors.password}
|
||||||
|
helperText={t('events.passwordHelperText', 'You can use dates like "04.07.2025" or any text with 6+ characters')}
|
||||||
leftIcon={<Lock className="w-5 h-5" />}
|
leftIcon={<Lock className="w-5 h-5" />}
|
||||||
rightIcon={
|
rightIcon={
|
||||||
<button
|
<button
|
||||||
|
|||||||
Reference in New Issue
Block a user