diff --git a/internal/api/password.go b/internal/api/password.go index 5ce20149b2..a1ffcf142e 100644 --- a/internal/api/password.go +++ b/internal/api/password.go @@ -9,7 +9,7 @@ import ( "github.com/supabase/auth/internal/api/apierrors" ) -// BCrypt hashed passwords have a 72 character limit +// BCrypt hashed passwords have a 72-byte limit const MaxPasswordLength = 72 // WeakPasswordError encodes an error that a password does not meet strength @@ -31,7 +31,7 @@ func (a *API) checkPasswordStrength(ctx context.Context, password string) error if len(password) > MaxPasswordLength { return apierrors.NewBadRequestError( apierrors.ErrorCodeValidationFailed, - "Password cannot be longer than %v characters", + "Password cannot be longer than %v bytes", MaxPasswordLength, ) } diff --git a/internal/api/password_test.go b/internal/api/password_test.go index 48e4b097fe..18868ab106 100644 --- a/internal/api/password_test.go +++ b/internal/api/password_test.go @@ -2,6 +2,8 @@ package api import ( "context" + "net/http" + "strings" "testing" "github.com/stretchr/testify/require" @@ -116,3 +118,36 @@ func TestPasswordStrengthChecks(t *testing.T) { } } } + +func TestPasswordStrengthMaximumLengthBytes(t *testing.T) { + api := &API{config: &conf.GlobalConfiguration{ + Password: conf.PasswordConfiguration{MinLength: 6}, + }} + + for _, tc := range []struct { + name string + password string + tooLong bool + }{ + {"ASCII at limit", strings.Repeat("a", 72), false}, + {"ASCII over limit", strings.Repeat("a", 73), true}, + {"Korean at limit", strings.Repeat("가", 24), false}, + {"Korean over limit", strings.Repeat("가", 25), true}, + {"emoji at limit", strings.Repeat("😀", 18), false}, + {"emoji over limit", strings.Repeat("😀", 19), true}, + } { + t.Run(tc.name, func(t *testing.T) { + err := api.checkPasswordStrength(context.Background(), tc.password) + if !tc.tooLong { + require.NoError(t, err) + return + } + + var httpErr *HTTPError + require.ErrorAs(t, err, &httpErr) + require.Equal(t, http.StatusBadRequest, httpErr.HTTPStatus) + require.Equal(t, apierrors.ErrorCodeValidationFailed, httpErr.ErrorCode) + require.Equal(t, "Password cannot be longer than 72 bytes", httpErr.Message) + }) + } +}