marthaegrimaldi / marthaegrimaldi/zomato-clone-app-source-code
Password requirements not enforced on Sign-Up Page — weak/non-compliant passwords are being saved
Nobody has claimed this yet.
- Dominant language
- JavaScript
- Stars
- 5
- Forks
- 8
- PR merge metrics
- No merged PRs in 30d
Description
Describe the bug
On the Enatega Multivendor sign-up page, passwords that do not meet the defined requirements are still accepted and the account is created. This allows weak or non-compliant passwords to be saved.
To Reproduce
Steps to reproduce the behavior:
Go to the Enatega Multivendor website sign-up page.
Fill in the required fields.
3.In the Password field, enter a password that does not meet the policy (e.g., pass123, abc, or any short/simple password).
Submit the form.
Notice the account is created / the form is saved without any password validation error.
Expected behavior
The system should reject passwords that do not meet the password policy (for example: minimum length, include uppercase, number, special character — whatever the site policy is) and show a clear error message explaining the requirements. Weak passwords must not be saved.
Desktop (please complete the following information):
OS: [e.g. Desktop]
Browser [e.g. chrome]
Version [e.g. 22]
Smartphone (please complete the following information):
Device: [e.g. iPhone6]
OS: [e.g. iOS8.1]
Browser [e.g. stock browser, safari]
Version [e.g. 22]
Additional context
Add any other context about the problem here.
Labels: Enatega Website, Bug
Contributor guide
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
Research direction
Start at the Enatega Multivendor sign-up page and trace how the Password field is validated before the form is submitted and the account is created. Reproduce the issue with pass123, abc, and another short or simple password; done means non-compliant passwords are rejected, a clear policy error is shown, and no account is saved.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- javascript
- Domain
- authentication, security
- Issue type
- Bug
- Difficulty
- 3/5
- Estimated time
- 1-2 days
- Activity status
- Quiet
- Clarity
- Needs clarification
- Newbie friendliness
- 45/100