diff --git a/packages/twenty-front/src/modules/auth/sign-in-up/hooks/useSignInUpForm.ts b/packages/twenty-front/src/modules/auth/sign-in-up/hooks/useSignInUpForm.ts index 6857d62ecb..916c218d76 100644 --- a/packages/twenty-front/src/modules/auth/sign-in-up/hooks/useSignInUpForm.ts +++ b/packages/twenty-front/src/modules/auth/sign-in-up/hooks/useSignInUpForm.ts @@ -26,7 +26,10 @@ const makeValidationSchema = (signInUpStep: SignInUpStep) => signInUpStep === SignInUpStep.Password ? z .string() - .regex(PASSWORD_REGEX, t`Password must be min. 8 characters`) + .regex( + PASSWORD_REGEX, + t`Password must be between 8 and 50 characters`, + ) : z.string().optional(), captchaToken: z.string().default(''), }) diff --git a/packages/twenty-front/src/modules/auth/utils/__tests__/passwordRegex.test.ts b/packages/twenty-front/src/modules/auth/utils/__tests__/passwordRegex.test.ts index adf01551c0..c3c4cb1448 100644 --- a/packages/twenty-front/src/modules/auth/utils/__tests__/passwordRegex.test.ts +++ b/packages/twenty-front/src/modules/auth/utils/__tests__/passwordRegex.test.ts @@ -8,4 +8,12 @@ describe('PASSWORD_REGEX', () => { expect(PASSWORD_REGEX.test(validPassword)).toBe(true); expect(PASSWORD_REGEX.test(invalidPassword)).toBe(false); }); + + it('should match passwords with at most 50 characters', () => { + const validPassword = 'a'.repeat(50); + const invalidPassword = 'a'.repeat(51); + + expect(PASSWORD_REGEX.test(validPassword)).toBe(true); + expect(PASSWORD_REGEX.test(invalidPassword)).toBe(false); + }); }); diff --git a/packages/twenty-front/src/modules/auth/utils/passwordRegex.ts b/packages/twenty-front/src/modules/auth/utils/passwordRegex.ts index 1e38ac7520..9bf1646b1c 100644 --- a/packages/twenty-front/src/modules/auth/utils/passwordRegex.ts +++ b/packages/twenty-front/src/modules/auth/utils/passwordRegex.ts @@ -1 +1 @@ -export const PASSWORD_REGEX = /^.{8,}$/; +export const PASSWORD_REGEX = /^.{8,50}$/; diff --git a/packages/twenty-front/src/pages/auth/PasswordReset.tsx b/packages/twenty-front/src/pages/auth/PasswordReset.tsx index d4502fbbb8..469bca0654 100644 --- a/packages/twenty-front/src/pages/auth/PasswordReset.tsx +++ b/packages/twenty-front/src/pages/auth/PasswordReset.tsx @@ -40,14 +40,14 @@ import { import { useNavigateApp } from '~/hooks/useNavigateApp'; import { logError } from '~/utils/logError'; -const passwordMinLengthMessage = msg`Password must be min. 8 characters`; +const passwordLengthMessage = msg`Password must be between 8 and 50 characters`; const validationSchema = z .object({ passwordResetToken: z.string(), newPassword: z .string() - .regex(PASSWORD_REGEX, i18n._(passwordMinLengthMessage)), + .regex(PASSWORD_REGEX, i18n._(passwordLengthMessage)), }) .required(); diff --git a/packages/twenty-server/src/engine/core-modules/auth/auth.util.ts b/packages/twenty-server/src/engine/core-modules/auth/auth.util.ts index 8e829cb6a2..cb483b7a4f 100644 --- a/packages/twenty-server/src/engine/core-modules/auth/auth.util.ts +++ b/packages/twenty-server/src/engine/core-modules/auth/auth.util.ts @@ -7,7 +7,7 @@ import { import * as bcrypt from 'bcrypt'; -export const PASSWORD_REGEX = /^.{8,}$/; +export const PASSWORD_REGEX = /^.{8,50}$/; const saltRounds = 10;