Comment 12 for bug 1013786

Revision history for this message
Galen Charlton (gmc) wrote : Re: [Bug 1013786] Re: tpac: Check for password strength at login

> I could probably do what Galen suggest in comment #10 to move the check
> to a self-contained routine in EGCatLoader::Util and add a test.

Thanks!

> I wonder if there should be a setting to disable this feature or not?
> Currently, a default is used if the password regex setting is not set.
> Maybe, it should only function if the setting is set as a way to disable
> this functionality. Alternately, YAOUS could be added to turn the
> checking off.

I'm neutral on whether or not it should be possible to disable the
feature (and to be clear, I mean the feature of "nagging upon login if
the password is weak per the regex), but if you write code to do it, I
suggest making a new YAOUS.