Several constraints use PHP Ctype functions for validation while JavaScript uses regular expressions. The logic is approximately, but not completely, the same, and it causes different validation results in some cases. For instance, using a Unicode character would pass the JS punctuation constraint validation but fail the PHP punctuation constraint validation. The PHP validation is also locale sensitive whereas JS validation is not. This means for certain locales a character considered alphanumeric by PHP, for instance, may not be considered alphanumeric by JS.

This problem reported by James Byng in #2797085: Add pound symbol (£) to punctuation constraint.

Comments

AohRveTPV created an issue. See original summary.

aohrvetpv’s picture

Status: Active » Needs review
StatusFileSize
new10.43 KB
aohrvetpv’s picture

Issue summary: View changes
aohrvetpv’s picture

Issue summary: View changes
aohrvetpv’s picture

Issue summary: View changes
aohrvetpv’s picture

Title: JavaScript and PHP constraint validation differs » PHP and JavaScript constraint validation differs
aohrvetpv’s picture

Status: Needs review » Needs work

Patch doesn't work. chr() returns the ASCII character corresponding to the integer, but not according to the character set used by the ctype functions for character classification.

aohrvetpv’s picture

I have been trying unsuccessfully to figure out a way in PHP to get a list of characters for each Ctype character class. Those character classes could then be specified in the JavaScript code that is generated for validating constraints. Then the JavaScript validation could match PHP validation.

I posted a question on Stack Overflow:
https://stackoverflow.com/questions/43898433/how-to-enumerate-and-print-...

aohrvetpv’s picture

Could not figure out a way to write/generate JavaScript to match the existing PHP logic, which uses ctype_* functions.

Instead, I rewrote the logic for both PHP and JS using regular expressions, borrowing code from 7.x-2.x. ctype_* functions are no longer used. The validation between PHP and JS should now be the same. The code is simpler, too, I think.

A downside of this change is characters that were previously counted by the ctype_* functions may not be with this new version. So, passwords that previous met constraints may no longer meet constraints. Hopefully this would affect a very limited number of sites.

aohrvetpv’s picture

Status: Needs work » Needs review
aohrvetpv’s picture

These changes need testing because they reimplement several of the commonly used constraints. I tested them more carefully than usual but could well have missed problems.

I think the best way to get the changes tested may be to commit and let them be tested through use of 7.x-1.x-dev. The impact of this bug is low enough that maybe no one will go through the trouble of reviewing and deliberately testing the patch.

  • AohRveTPV committed e38b026 on 7.x-1.x
    Issue #2876719 by AohRveTPV: PHP and JavaScript constraint validation...
aohrvetpv’s picture

Status: Needs review » Fixed

Status: Fixed » Closed (fixed)

Automatically closed - issue fixed for 2 weeks with no activity.