Index: user.js
===================================================================
RCS file: /cvs/drupal/drupal/modules/user/user.js,v
retrieving revision 1.6
diff -u -p -r1.6 user.js
--- user.js	12 Sep 2007 18:29:32 -0000	1.6
+++ user.js	29 Nov 2008 06:00:11 -0000
@@ -125,6 +125,7 @@ Drupal.evaluatePasswordStrength = functi
   var hasNumbers = value.match(/[0-9]+/);
   var hasPunctuation = value.match(/[^a-zA-Z0-9]+/);
   var hasCasing = value.match(/[a-z]+.*[A-Z]+|[A-Z]+.*[a-z]+/);
+  var hasRecurring = value.match(/[a-z]{3,}|[A-Z]{3,}|[0-9]{3,}|[^a-zA-Z0-9]{3,}/);
 
   // Check if the password is blank.
   if (!value.length) {
@@ -142,13 +143,13 @@ Drupal.evaluatePasswordStrength = functi
     msg = translate.sameAsUsername;
   }
   // Check if it contains letters, numbers, punctuation, and upper/lower case.
-  else if (hasLetters && hasNumbers && hasPunctuation && hasCasing) {
+  else if (hasLetters && hasNumbers && hasPunctuation && hasCasing && !hasRecurring) {
     strength = "high";
   }
   // Password is not secure enough so construct the medium-strength message.
   else {
     // Extremely bad passwords still count as low.
-    var count = (hasLetters ? 1 : 0) + (hasNumbers ? 1 : 0) + (hasPunctuation ? 1 : 0) + (hasCasing ? 1 : 0);
+    var count = (hasLetters ? 1 : 0) + (hasNumbers ? 1 : 0) + (hasPunctuation ? 1 : 0) + (hasCasing ? 1 : 0) + (!hasRecurring ? 1 : 0);
     strength = count > 1 ? "medium" : "low";
 
     msg = [];
@@ -161,6 +162,9 @@ Drupal.evaluatePasswordStrength = functi
     if (!hasPunctuation) {
       msg.push(translate.addPunctuation);
     }
+    if (hasRecurring) {
+      msg.push(translate.addVariation);
+    }
     msg = translate.needsMoreVariation +"<ul><li>"+ msg.join("</li><li>") +"</li></ul>";
   }
 
