gray-mueller / gray-mueller/zomato-clone-app-using-react-native

Password requirements not enforced on Sign-Up Page — weak/non-compliant passwords are being saved

Open
#2,311 0 comments 0 reactions 0 assignees View on GitHub
Dominant language
JavaScript
Stars
0
Forks
0
PR merge metrics
No merged PRs in 30d

Description

Describe the bug
On the Enatega Multivendor sign-up page, passwords that do not meet the defined requirements are still accepted and the account is created. This allows weak or non-compliant passwords to be saved.

To Reproduce
Steps to reproduce the behavior:

Go to the Enatega Multivendor website sign-up page.
Fill in the required fields.
3.In the Password field, enter a password that does not meet the policy (e.g., pass123, abc, or any short/simple password).
Submit the form.
Notice the account is created / the form is saved without any password validation error.
Expected behavior
The system should reject passwords that do not meet the password policy (for example: minimum length, include uppercase, number, special character — whatever the site policy is) and show a clear error message explaining the requirements. Weak passwords must not be saved.

Desktop (please complete the following information):

OS: [e.g. Desktop]
Browser [e.g. chrome]
Version [e.g. 22]
Smartphone (please complete the following information):

Device: [e.g. iPhone6]
OS: [e.g. iOS8.1]
Browser [e.g. stock browser, safari]
Version [e.g. 22]
Additional context
Add any other context about the problem here.

Labels: Enatega Website, Bug

Contributor guide

Open the contributing guide

Research direction

Start at the sign-up page's password handling and reproduce the issue with the examples in the report, such as pass123 and abc. Determine the password policy used by the site and trace where the form submission accepts the password. Done means non-compliant passwords are rejected, a clear requirements message is shown, and weak passwords are not saved.

Written by the indexing model from the issue text.

Assessment

Tech stack
javascript, react-native
Domain
authentication, frontend
Issue type
Bug
Difficulty
3/5
Estimated time
1-2 days
Activity status
Active
Clarity
Needs clarification
Newbie friendliness
45/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.