nextcloud / nextcloud/password_policy
Additional password strength checks
Open
Nobody has claimed this yet.
enhancement
- Dominant language
- PHP
- Stars
- 39
- Forks
- 27
- Avg merge
- 1h 36m
- Merged PRs (30d)
- 10
Description
It would be good to increase the security a bit by not allowing the following things:
- There is no check on repeated characters more then 4 Times (AAAAbI$% should not be allowed)
- There is no check that keyboard patterns which are vertically or horizontally next to each other should not be used (QUERTY789)
Contributor guide
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
Research direction
No file, test, or entry point is named in the issue. Start by locating the existing password validation logic and its tests, then verify how repeated characters and keyboard-adjacent patterns are currently handled. Done means both listed examples, and equivalent patterns, are rejected without breaking the existing password rules.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- php
- Domain
- authentication, security
- Issue type
- Feature
- Difficulty
- 4/5
- Estimated time
- 3-5 days
- Activity status
- Stale
- Clarity
- Mostly clear
- Newbie friendliness
- 38/100