Skip to content

basalt / auth/src / PasswordPolicy

Interface: PasswordPolicy ​

Defined in: auth/src/routes.ts:20

How strong a password has to be.

The rule was min(8), fixed, with no way to change it — the 2012 minimum, in routes an application either uses as they are or replaces wholesale. One that needed more reached into the route's Zod object and swapped the field, depending on the internal shape of a body it does not own.

A whole schema and not just a number, because the interesting rules are not lengths: "at least one symbol", "not the email address", "not in a breach list". An option taking only a number would send those applications straight back to patching.

Properties ​

minLength? ​

> optional minLength?: number

Defined in: auth/src/routes.ts:21

Released under the MIT License.