Problem
Currently, the sign-up system accepts any arbitrary string as a password, including weak or short passwords (e.g., 123, admin, or single-character passwords). This exposes users to easy credential cracking and basic security vulnerabilities.
Proposed Improvement
This PR introduces robust password strength validation on both the client-side (frontend) and server-side (backend):
- Client-side UX Validation: Added a real-time password strength meter/indicator on the sign-up page. The password must satisfy:
- Minimum length of 8 characters.
- At least one uppercase letter.
- At least one lowercase letter.
- At least one digit.
- At least one special character (e.g.,
@, $, !, %, *, ?, &).
- Backend API Validation: Added validation rules on the
/register endpoint before hashing the password with bcrypt. If the password fails criteria check, it returns a 400 Bad Request with descriptive validation messages.
Why improvement is needed
Implementing password complexity rules is a standard security best practice. It protects users from weak credentials, helps secure their study data, and elevates the platform to production-grade standards.
Expected Result
- Frontend UI: The sign-up button is disabled until a valid, strong password is typed, showing dynamic requirements that check off as the user types.
- Backend API: Invalid password requests are rejected immediately, preventing weak entries from being written to the database.
Alternatives Considered
- Third-party libraries (e.g.,
zod, express-validator): Decided to use a lightweight regex validation pattern instead of adding external dependencies to keep the project light and avoid inflating node_modules for a single validation requirement.
- Client-side only validation: Bypassing frontend checks is easy via tools like Postman, so backend-level validation was also implemented to ensure security integrity.
Additional Context
(Note: You can attach a screenshot or GIF here showing the password validator UI state)
Problem
Currently, the sign-up system accepts any arbitrary string as a password, including weak or short passwords (e.g.,
123,admin, or single-character passwords). This exposes users to easy credential cracking and basic security vulnerabilities.Proposed Improvement
This PR introduces robust password strength validation on both the client-side (frontend) and server-side (backend):
@,$,!,%,*,?,&)./registerendpoint before hashing the password withbcrypt. If the password fails criteria check, it returns a400 Bad Requestwith descriptive validation messages.Why improvement is needed
Implementing password complexity rules is a standard security best practice. It protects users from weak credentials, helps secure their study data, and elevates the platform to production-grade standards.
Expected Result
Alternatives Considered
zod,express-validator): Decided to use a lightweight regex validation pattern instead of adding external dependencies to keep the project light and avoid inflatingnode_modulesfor a single validation requirement.Additional Context
(Note: You can attach a screenshot or GIF here showing the password validator UI state)