[aur-dev] [PATCH 1/3] Check password length on the password reset form

archlinux at cryptocrack.de archlinux at cryptocrack.de
Fri Nov 21 10:45:12 UTC 2014


From: Lukas Fleischer <archlinux at cryptocrack.de>

We already check for a minimum password length on the account edit page.
Add the same check to the password reset form (which is also used to set
an initial password).

Signed-off-by: Lukas Fleischer <archlinux at cryptocrack.de>
---
 web/html/passreset.php | 4 ++++
 1 file changed, 4 insertions(+)

diff --git a/web/html/passreset.php b/web/html/passreset.php
index 9d8e1ae..fecefe4 100644
--- a/web/html/passreset.php
+++ b/web/html/passreset.php
@@ -25,6 +25,10 @@ if (isset($_GET['resetkey'], $_POST['email'], $_POST['password'], $_POST['confir
 		$error = __('Missing a required field.');
 	} elseif ($password != $confirm) {
 		$error = __('Password fields do not match.');
+	} elseif (!good_passwd($password)) {
+		$length_min = config_get_int('options', 'passwd_min_len');
+		$error = __("Your password must be at least %s characters.",
+			$length_min);
 	} elseif ($uid == null) {
 		$error = __('Invalid e-mail.');
 	}
-- 
2.1.3


More information about the aur-dev mailing list