feat(auth): set 50-character maximum length on passwords (#20655)

## Summary
- Cap password length at 50 characters in the shared regex used by
sign-up, password reset, and password change (both `twenty-front` and
`twenty-server`).
- Update the user-facing validation message on sign-up and password
reset to mention both the 8 min and 50 max bounds.
- Extend the `PASSWORD_REGEX` unit test to cover the new upper bound.

The cap also prevents unbounded inputs from reaching bcrypt, which
silently truncates passwords above 72 bytes and can mask user-visible
bugs.

## Test plan
- [x] `npx jest src/modules/auth/utils/__tests__/passwordRegex.test.ts`
passes (8-char min and 50-char max).
- [ ] Sign up with a 51-character password — form rejects with "Password
must be between 8 and 50 characters".
- [ ] Sign up with an 8–50 character password — succeeds.
- [ ] Password reset rejects a 51-character password with the same
message.
- [ ] Existing users with longer passwords (if any pre-exist) can still
sign in (the regex only gates write paths: sign-up, change, reset).
This commit is contained in:
Félix Malfait
2026-05-18 10:12:19 +02:00
committed by GitHub
parent 62b347fc74
commit 6b49a14b9f
5 changed files with 16 additions and 5 deletions
@@ -7,7 +7,7 @@ import {
import * as bcrypt from 'bcrypt';
export const PASSWORD_REGEX = /^.{8,}$/;
export const PASSWORD_REGEX = /^.{8,50}$/;
const saltRounds = 10;