ajoao
Groups in regex to validate password
I need to validate the criteria in a password: Must contain at least one capital letter, one lowercase and one or more numbers, the size must be between 6 and 32 characters, can not have any special character or space. Must have all 3 types: Uppercase, lowercase and number.
I have tried several ways but I could not, I looked in the documentation of regex (Elixir and Perl), but I caught here: Regex.run(~r/^[A-Z](?=.*)[a-z](?=.*)[^\W_]{5,30}$/,IO.gets"")
But this regex only allows password starting with the uppercase and does not allow numbers, if I add something like \d(?=.*) or [0-9](?=.*) nothing works.
Just as an example in ES/JS would be: /^(?=.*[A-Z])(?=.*[a-z])(?=.*\d)[^\W_]{6,32}$/
Most Liked
riverrun
I have worked on this password strength checker for some time, and it’s recently been updated to work with the newer NIST recommendations. As well as checking length and for certain common combinations, it also checks for common passwords (with certain changes made to them, like leet substitution, characters added to the beginning / end of the common password, etc.), and the common password list is configurable.
Having said that, in many cases I would recommend a good front-end solution, such as the previously mentioned zxcvbn, which also checks for common passwords (with changes). The reason why I am suggesting zxcvbn is that it provides more immediate feedback to the user, and that can be very useful when encouraging users to choose strong passwords.
techgaun
Sorry to bump an old thread but this was something that I needed as well. I went ahead and ported the zxcvbn for Elixir. Hopefully, this turns out to be useful for others coming back to this thread.
axelson
@ajoao or anyone else interested in this. Partially inspired by this thread (and the fact that there didn’t appear to be any password validators or checkers on hex) I’ve created a simple password validator library:
The original requirements would look like this with PasswordValidator:
opts = [
length: [min: 6, max: 32],
character_set: [
lower_case: 1, # at least one lower case letter
upper_case: 1, # at least one capital letter
numbers: 1, # at least one numbers
special: [0, 0], # no special characters allowed
]
]
changeset
|> PasswordValidator.validate(:password, opts)
Please feel free to check it out and give me any feedback (including on the code structure). I’ll probably try to do some sort of larger forum post in the near future but wanted to mention it here first.
axelson
Yeah that would be a great next step! 
But actually that led me to zxcvbn which is an entropy-based checker. That would be interesting to tackle and is currently missing an Elixir implementation. Also I am agreed that validating based on types of characters is not very useful (but I really just wanted to try my hand at a library).
axelson
Just released version 0.3.0 of GitHub - axelson/password-validator: A Elixir library to validate passwords, with built-in validators for password length as well as the character sets used with support for zxcvbn via @techgaun’s zxcvbn-elixir ![]()







