Skip to content

feat: Add client-side and server-side password strength validation #1248

Description

@vansh2604-star

Problem

Currently, the sign-up system accepts any arbitrary string as a password, including weak or short passwords (e.g., 123, admin, or single-character passwords). This exposes users to easy credential cracking and basic security vulnerabilities.

Proposed Improvement

This PR introduces robust password strength validation on both the client-side (frontend) and server-side (backend):

  1. Client-side UX Validation: Added a real-time password strength meter/indicator on the sign-up page. The password must satisfy:
    • Minimum length of 8 characters.
    • At least one uppercase letter.
    • At least one lowercase letter.
    • At least one digit.
    • At least one special character (e.g., @, $, !, %, *, ?, &).
  2. Backend API Validation: Added validation rules on the /register endpoint before hashing the password with bcrypt. If the password fails criteria check, it returns a 400 Bad Request with descriptive validation messages.

Why improvement is needed

Implementing password complexity rules is a standard security best practice. It protects users from weak credentials, helps secure their study data, and elevates the platform to production-grade standards.

Expected Result

  • Frontend UI: The sign-up button is disabled until a valid, strong password is typed, showing dynamic requirements that check off as the user types.
  • Backend API: Invalid password requests are rejected immediately, preventing weak entries from being written to the database.

Alternatives Considered

  • Third-party libraries (e.g., zod, express-validator): Decided to use a lightweight regex validation pattern instead of adding external dependencies to keep the project light and avoid inflating node_modules for a single validation requirement.
  • Client-side only validation: Bypassing frontend checks is easy via tools like Postman, so backend-level validation was also implemented to ensure security integrity.

Additional Context

(Note: You can attach a screenshot or GIF here showing the password validator UI state)

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    enhancementNew feature or request

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions