fix: enforce password length and complexity in UserRegister schema#2224
Merged
janavipandole merged 1 commit intoJun 13, 2026
Merged
Conversation
|
@nyxsky404 is attempting to deploy a commit to the janavipandole's projects Team on Vercel. A member of the Team first needs to authorize it. |
Contributor
Author
CI Failures — Pre-existing Repository IssuesThe following failing checks are not caused by the changes in this PR. This PR only modifies Python backend files; none of the failures below involve those files.
These need to be addressed at the repository infrastructure level by a maintainer and are unrelated to this contribution. |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
📄 Description
Adds server-side password validation to the
UserRegisterPydantic schema so thePOST /api/auth/registerendpoint rejects weak passwords before they reach the bcrypt layer.Rules enforced:
username: minimum 3 characters, maximum 30 characterspassword: minimum 8 characters, maximum 128 characterspasswordmust contain at least one uppercase letter (A–Z)passwordmust contain at least one digit (0–9)UserLoginis intentionally unchanged — it only authenticates against what is already stored.Files changed:
backend/app/schemas.py: addedfield_validatorandreimports; appliedFieldconstraints tousernameandpassword; addedpassword_complexityvalidator onUserRegister🔗 Related Issues
Fixes #2218
🧩 Type of Change
Verification & Testing
Local Verification
Devices/Browsers Tested
✅ Checklist