Conversation
## Because - The change-password form checked the length of the new password only, so eight spaces passed. - A user who saved a space-only password could not sign in again. The sign-in form rejects it. ## This pull request - Adds a trim check to the `length` validator in `FormPassword`. It is the predicate `FormPasswordWithInlineCriteria` already uses. - Adds two tests: a space-only password is rejected, and a space-padded password with real content still works. ## Issue that this pull request solves Closes: https://mozilla-hub.atlassian.net/browse/FXA-9473
Contributor
There was a problem hiding this comment.
Pull request overview
Rejects whitespace-only passwords while preserving valid space-padded passwords.
Changes:
- Adds non-whitespace validation to
FormPassword. - Tests rejection and valid padding behavior.
Reviewed changes
Copilot reviewed 2 out of 2 changed files in this pull request and generated no comments.
| File | Description |
|---|---|
FormPassword/index.tsx |
Rejects whitespace-only new passwords. |
FormPassword/index.test.tsx |
Covers whitespace-only and padded passwords. |
💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Because
This pull request
lengthvalidator inFormPassword. It is the predicateFormPasswordWithInlineCriteriaalready uses.Issue that this pull request solves
Closes: https://mozilla-hub.atlassian.net/browse/FXA-9473
Checklist
Put an
xin the boxes that applyHow to review (Optional)
lengthvalidator inFormPassword/index.tsx.value.length > 7 && value.trim() !== ''. The shortervalue.trim().length > 7also rejects a valid padded password such as" abc123 ", which locks out users whose password has padding.Screenshots (Optional)
None. The failure shows on the existing "At least 8 characters" row, so there is no new copy and no layout change.
Other information (Optional)
PageCreatePasswordhad the same bug. It andPageChangePasswordboth renderFormPassword, so this one change fixes both pages.FormPassword,PageChangePassword, andPageCreatePasswordspecs, 40 tests pass. Lint passes forfxa-settings.