Skip to content

Add configurable password strength validation - #124

Merged
strider2038 merged 2 commits into
mainfrom
feat/password-strength
Oct 2, 2026
Merged

strider2038 merged 2 commits into
mainfrom
feat/password-strength

Conversation

@strider2038

@strider2038 strider2038 commented Oct 2, 2026 •

Copy link
Copy Markdown
Contributor

Adds local password-strength validation with it.HasPasswordStrength(), standalone validate.PasswordStrength, and validate.EstimatePasswordStrength for score displays. The default minimum is Medium (2), configurable from Weak (1) to VeryStrong (4).

The estimator reproduces Symfony 8.0's byte-based entropy heuristic without dictionaries, sequence detection, normalization, dependencies, or network requests. README documents its limitations, including high scores for predictable sequences. Custom estimators can replace the algorithm; out-of-range scores and invalid minimums produce configuration errors, and nil estimators restore the default.

Nil pointers are skipped. Empty strings are evaluated and rejected by the default estimator, matching Symfony. Violations only receive strength/minimum parameters, never the password automatically. Includes customizable errors/messages, groups, generic This/Each support, English/Russian translations, examples, and an Unreleased changelog entry.

Validation: bash scripts/test-all.sh passed (formatting, vet, golangci-lint v2.13.2, unit and race tests, module tidy and verification). Tests cover Symfony reference examples, all category/score thresholds, repeats and UTF-8 examples, custom estimators and invalid configurations, empty input, translations, and absence of password data in violation parameters.

Closes #109.

@strider2038
strider2038 merged commit 2848cbb into main Oct 2, 2026
3 of 4 checks passed
@strider2038
strider2038 deleted the feat/password-strength branch October 2, 2026 16:43
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Constraint: PasswordStrength

1 participant