It's easy to set password constraints in Laravel. Recently, a change was introduced to make some of the convenience methods more consistent. This is lovely, but the comments in the PR surprised me!
As it turns out, bcrypt ignores everything after 72 characters. The OWASP security standards also recommend setting a password character limit - probably for these reasons.
Future versions of Laravel, perhaps Laravel 11, will potentially default this to 72 characters.
But don't wait until then.
Ensure you are setting a password character limit using one of the methods within the video with your applications today!
---
Pull Request: https://github.com/laravel/framework/...
---
Website: https://acairns.co.uk
Twitter: / andrewcairns
Patreon: / metaphoricallyspeaking
Discord: https://acairns.co.uk/discord
Substack: https://acairns.substack.com
#laravel #php #phpc