nextcloud / nextcloud/password_policy

Additional password strength checks

Open
#123 0 comments 2 reactions 0 assignees View on GitHub

Nobody has claimed this yet.

enhancement
Dominant language
PHP
Stars
39
Forks
27
Avg merge
1h 36m
Merged PRs (30d)
10

Description

It would be good to increase the security a bit by not allowing the following things:

  1. There is no check on repeated characters more then 4 Times (AAAAbI$% should not be allowed)
  2. There is no check that keyboard patterns which are vertically or horizontally next to each other should not be used (QUERTY789)

Contributor guide

Open the contributing guide

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

Research direction

No file, test, or entry point is named in the issue. Start by locating the existing password validation logic and its tests, then verify how repeated characters and keyboard-adjacent patterns are currently handled. Done means both listed examples, and equivalent patterns, are rejected without breaking the existing password rules.

Written by the indexing model from the issue text.

Assessment

Tech stack
php
Domain
authentication, security
Issue type
Feature
Difficulty
4/5
Estimated time
3-5 days
Activity status
Stale
Clarity
Mostly clear
Newbie friendliness
38/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.