Are there any special password requirements (except the min. 8 chars) if I try to manually set a new password for a user in MODX backend? I try to enter a new password which is 8 chars long abcdef:) (ends with colon + closing parentheses) but MODX tells me Password is not valid. Why should this password not be valid?
I found this in /core/model/modx/processors/security/user/_validation.php
} elseif (!preg_match('/^[^\'\\x3c\\x3e\\(\\);\\x22]+$/', $specifiedPassword)) {
$this->processor->addFieldError('specifiedpassword', $this->modx->lexicon('user_err_password_invalid'));
Seems that ( and ) are really forbidden?
Yes. AFAIK, the only thing you can do is change the required length.
discuss.answer
Quote from: BobRay at Mar 28, 2017, 01:05 PMYes. AFAIK, the only thing you can do is change the required length.
Do you have a clue why ( ) ' \ should not be allowed in MODx passwords? This is a real problem in systems with a lot of user registrations. The current project has about 10.000 users/customers (it's an online shop) and the shop owner gets support requests regarding this password restriction.
Should I file a bug report on GitHub?
I'm just guessing, but maybe it's because it's an escape character in PHP strings and is itself ignored in certain situations.
It doesn't appear to be caught by that regex. Is there no warning for it? If so, that would be a bug worth reporting.
Sigh. One more reason to hate ExtJS.