Skip to content

v1.4.1 deviates from the javscript version of zxcvbn #84

@JohanMouritsen

Description

@JohanMouritsen

in this commit:
603e015
the regex for checking if a recent year is in the password was changed to include future and more present years.
While this is probably better, it is not in line with the original zxcvbn library:
https://github.com/dropbox/zxcvbn/blob/67c4ece9efc40c9d0a1d7d995b2b22a91be500c2/src/matching.coffee#L38

As such if you rely on both your front and backend to do these checks, then a password like this:
xvjcz2025
is a 2 on the php version, but a 3 on the javascript version.

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions