Conversation
This branch has not been deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Background
checkPasswordStrengthenforces bcrypt's 72-byte input limit using Go'slen(password), which counts bytes. However, the error message saysPassword cannot be longer than 72 characters, and the accompanying comment also describes a character limit.This is misleading for multibyte UTF-8 passwords. For example, 25 repetitions of
가contain only 25 characters but occupy 75 bytes, so they are rejected by a message that appears to allow up to 72 characters. The validation already rejects over-limit input; the bug is the unit reported to the user.Changes
Password cannot be longer than %v characterstoPassword cannot be longer than %v bytes.72-byte limit.Testing
Run the focused tests from the repository root:
The new test covers these inputs:
arepeated 72 timesarepeated 73 times가repeated 24 times가repeated 25 times😀repeated 18 times😀repeated 19 timesFor every rejected input, the test asserts HTTP 400, the
validation_failederror code, and the exact messagePassword cannot be longer than 72 bytes.Verification performed with Go 1.27.0 in the repository's Docker base image:
charactersinstead ofbytes. All three at-limit cases passed.TestPasswordStrengthCheckspassed.gofmt -sformatting check andgit diff --checkpassed.Review Notes
checkPasswordStrengthdirectly and do not require a database. They verify validation and error fields, rather than end-to-end HTTP responses.