gray-mueller / gray-mueller/online-food-ordering-system-using-java

Password requirements not enforced on Sign-Up Page — weak/non-compliant passwords are being saved

Open
#2,051 0 comments 0 reactions 0 assignees View on GitHub
Dominant language
JavaScript
Stars
0
Forks
1
PR merge metrics
No merged PRs in 30d

Description

Describe the bug
On the Enatega Multivendor sign-up page, passwords that do not meet the defined requirements are still accepted and the account is created. This allows weak or non-compliant passwords to be saved.

To Reproduce
Steps to reproduce the behavior:

Go to the Enatega Multivendor website sign-up page.
Fill in the required fields.
3.In the Password field, enter a password that does not meet the policy (e.g., pass123, abc, or any short/simple password).
Submit the form.
Notice the account is created / the form is saved without any password validation error.
Expected behavior
The system should reject passwords that do not meet the password policy (for example: minimum length, include uppercase, number, special character — whatever the site policy is) and show a clear error message explaining the requirements. Weak passwords must not be saved.

Desktop (please complete the following information):

OS: [e.g. Desktop]
Browser [e.g. chrome]
Version [e.g. 22]
Smartphone (please complete the following information):

Device: [e.g. iPhone6]
OS: [e.g. iOS8.1]
Browser [e.g. stock browser, safari]
Version [e.g. 22]
Additional context
Add any other context about the problem here.

Labels: Enatega Website, Bug

Contributor guide

Open the contributing guide

Research direction

Start by reproducing the issue on the Enatega Multivendor sign-up page with the example passwords pass123 and abc, then trace the sign-up form's password validation and submission path. Done means passwords that fail the site's defined policy are rejected before account creation and a clear requirements error is shown.

Written by the indexing model from the issue text.

Assessment

Tech stack
javascript
Domain
authentication
Issue type
Bug
Difficulty
3/5
Estimated time
1-2 days
Activity status
Active
Clarity
Needs clarification
Newbie friendliness
45/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.