Context
Found while probing password_verify() behaviour for UserRepository::authenticate() and checking whether an empty password could reach password_hash().
Data
RegistrationDataFilter (src/InputFilter/RegistrationDataFilter.php) declares passwordHash with only required => true and no validators.
- Empty input is rejected:
required plus Laminas allow_empty defaulting to false (vendor/laminas/laminas-inputfilter/src/Input.php:63) yields "Value is required and can't be empty". Mismatch is rejected by Identical on confirmPasswordHash.
- Nothing constrains length or composition. Probed against the real filter wiring (
InputFilterHelper::registrationDataFilter()): passwordHash => 'a' with confirmPasswordHash => 'a' returns valid with value 'a'.
- That value is hashed at
src/Entity/User.php:310 (password_hash($passwordHash, PASSWORD_DEFAULT)).
UpdateUserDataFilter has no password field at all, so password changes never pass through a filter.
Available validator
Axleus\Validator\PasswordRequirement — src/PasswordRequirement.php, options length, upper, lower, digit, special, each defaulting to 0; at defaults it enforces nothing, so a minimum requires an explicit length.
- The validator lives in the project's legacy axleus org, which is migrating to webware components; the axleus GitHub org is closed, so the source today is the local checkout
/home/jsmith/github.com/axleus/axleus-validator, master @ c8c65ae.
- The webware validator component does not exist yet, so the validator is not consumable from
webinertia yet.
- The same source also ships
Axleus\Validator\DbStoredPassword.
Deferred - not part of this round.
Context
Found while probing
password_verify()behaviour forUserRepository::authenticate()and checking whether an empty password could reachpassword_hash().Data
RegistrationDataFilter(src/InputFilter/RegistrationDataFilter.php) declarespasswordHashwith onlyrequired => trueand no validators.requiredplus Laminasallow_emptydefaulting to false (vendor/laminas/laminas-inputfilter/src/Input.php:63) yields "Value is required and can't be empty". Mismatch is rejected byIdenticalonconfirmPasswordHash.InputFilterHelper::registrationDataFilter()):passwordHash => 'a'withconfirmPasswordHash => 'a'returns valid with value'a'.src/Entity/User.php:310(password_hash($passwordHash, PASSWORD_DEFAULT)).UpdateUserDataFilterhas no password field at all, so password changes never pass through a filter.Available validator
Axleus\Validator\PasswordRequirement—src/PasswordRequirement.php, optionslength,upper,lower,digit,special, each defaulting to0; at defaults it enforces nothing, so a minimum requires an explicitlength./home/jsmith/github.com/axleus/axleus-validator,master@c8c65ae.webinertiayet.Axleus\Validator\DbStoredPassword.Deferred - not part of this round.