The web's password forms read the server's minimum length
The server's MIN_PASSWORD_LEN was 8, and the web wrote 8 out five times: two checks and three placeholders. The constant moves beside the other policy numbers in settings.py (auth.py imports it), /api/config serves it as min_password_length, and the config store hands it to Register, Reset and Account. 8 stays only as the fallback until the config answers. DRY pass #2, batch 3 (#5372). Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
This commit is contained in:
@@ -24,8 +24,8 @@ const loading = ref(false);
|
||||
|
||||
async function submit() {
|
||||
error.value = "";
|
||||
if (password.value.length < 8) {
|
||||
error.value = "Password must be at least 8 characters.";
|
||||
if (password.value.length < config.minPasswordLength) {
|
||||
error.value = `Password must be at least ${config.minPasswordLength} characters.`;
|
||||
return;
|
||||
}
|
||||
loading.value = true;
|
||||
@@ -80,7 +80,7 @@ async function submit() {
|
||||
label="Password"
|
||||
type="password"
|
||||
autocomplete="new-password"
|
||||
placeholder="At least 8 characters"
|
||||
:placeholder="`At least ${config.minPasswordLength} characters`"
|
||||
required
|
||||
/>
|
||||
<p
|
||||
|
||||
Reference in New Issue
Block a user