Closed (fixed)
Project:
Password Policy
Version:
7.x-1.x-dev
Component:
Code
Priority:
Normal
Category:
Bug report
Assigned:
Unassigned
Reporter:
Created:
8 May 2017 at 18:44 UTC
Updated:
20 Jun 2017 at 18:49 UTC
Jump to comment: Most recent, Most recent file
Comments
Comment #2
aohrvetpv commentedComment #3
aohrvetpv commentedComment #4
aohrvetpv commentedComment #5
aohrvetpv commentedComment #6
aohrvetpv commentedComment #7
aohrvetpv commentedPatch doesn't work.
chr()returns the ASCII character corresponding to the integer, but not according to the character set used by the ctype functions for character classification.Comment #8
aohrvetpv commentedI have been trying unsuccessfully to figure out a way in PHP to get a list of characters for each Ctype character class. Those character classes could then be specified in the JavaScript code that is generated for validating constraints. Then the JavaScript validation could match PHP validation.
I posted a question on Stack Overflow:
https://stackoverflow.com/questions/43898433/how-to-enumerate-and-print-...
Comment #9
aohrvetpv commentedCould not figure out a way to write/generate JavaScript to match the existing PHP logic, which uses
ctype_*functions.Instead, I rewrote the logic for both PHP and JS using regular expressions, borrowing code from 7.x-2.x.
ctype_*functions are no longer used. The validation between PHP and JS should now be the same. The code is simpler, too, I think.A downside of this change is characters that were previously counted by the
ctype_*functions may not be with this new version. So, passwords that previous met constraints may no longer meet constraints. Hopefully this would affect a very limited number of sites.Comment #10
aohrvetpv commentedComment #11
aohrvetpv commentedThese changes need testing because they reimplement several of the commonly used constraints. I tested them more carefully than usual but could well have missed problems.
I think the best way to get the changes tested may be to commit and let them be tested through use of 7.x-1.x-dev. The impact of this bug is low enough that maybe no one will go through the trouble of reviewing and deliberately testing the patch.
Comment #13
aohrvetpv commented