signoz
signoz copied to clipboard
signup fails
Bug description
data:image/s3,"s3://crabby-images/89b45/89b456418bcb2c4b608a9e5ff6160262b6a8a865" alt="Screen Shot 2022-10-03 at 10 05 47"
http://localhost:3301/signup
According to screenshot, password policies are a) a pain b) useless if not implemented correctly c) not worth a dime - as many studies and reports found out before. why not drop them?
Expected behavior
i can sign up / log in.
How to reproduce
- $ cd deploy/docker/clickhouse-setup
- $ docker compose up
- $ open http://localhost:3301/signup
- see screenshot
Version information
- Signoz version: 0.11.1 (docker > create
- Browser version: chrome 10x.y
Thanks for opening this issue. A team member should give feedback soon. In the meantime, feel free to check out the contributing guidelines.
submit a PR to change it
@palashgdev can you check what's the issue here?
Thanks for reporting the issue. This is not expected. Is there a particular type of passwords you see this repeating on ? Cause this works well for some passwords I tried @tomquas
it is due to regex is failing at https://github.com/SigNoz/signoz/blob/develop/frontend/src/pages/SignUp/utils.ts#L10
we can add :
Awesome project but you really need to get rid of this arbitrary password requirements that were enforced and thought to be secure (which are not, by today's standards) by some random IT security guy in 1980s. Please Just enforce a length constraint and be done with it. Otherwise you'll keep adding more gibberish to your regex.
For instance, I wanted to sign up on my local copy, but it did not accept a couple of my passwords, which I use to access sites with arbitrary password requirements. These included a "(" and a '/' and a ";" that are not accepted.
Hey @pranay01 would love to take a stab at this. So what are we going with - adding : to regex or removing the special character constraint.
Hey, I would like to pick this up if no one else is working on it. I would simplify the check to just look for 8 characters, as those other constrains do not significantly improve security but negatively impact user experience and are generally considered outdated. Feel free to assign me.
@mariuskimmina Sure, please just reduce check to 8 chars. Assigned it to you
Feel free to join our slack community as well if you need any help