neatnik / omg.lol

Cool stuff for omg.lol
MIT License
360 stars 48 forks source link

Establish password policy #203

Open newbold opened 2 years ago

newbold commented 2 years ago

Currently there are no limitations regarding passwords — a password can be any length and consist of any combination of characters. But this also means that omg.lol allows for very weak passwords (even a single character, if you're a madlad). We need an improved password policy that allows for flexibility while discouraging weak or ineffective passwords.

newbold commented 2 years ago

Suggested: https://github.com/dropbox/zxcvbn

newbold commented 2 years ago

Also tap into: https://haveibeenpwned.com/API/v2

newbold commented 2 years ago

https://feedback.omg.lol/16604909894507