Password character limits

Опубликовано: 05 Ноябрь 2024
на канале: Metaphorically Speaking
329
7

It's easy to set password constraints in Laravel. Recently, a change was introduced to make some of the convenience methods more consistent. This is lovely, but the comments in the PR surprised me!

As it turns out, bcrypt ignores everything after 72 characters. The OWASP security standards also recommend setting a password character limit - probably for these reasons.

Future versions of Laravel, perhaps Laravel 11, will potentially default this to 72 characters.

But don't wait until then.

Ensure you are setting a password character limit using one of the methods within the video with your applications today!

---

Pull Request: https://github.com/laravel/framework/...

---

Website: https://acairns.co.uk
Twitter:   / andrewcairns  
Patreon:   / metaphoricallyspeaking  
Discord: https://acairns.co.uk/discord
Substack: https://acairns.substack.com

#laravel #php #phpc