Jump to content
theoden

New site fails with passwords containing special characters

Recommended Posts

Developers of the new web-site, please, recheck twice if you (via your magnificent web-framework, ofc) do not escape password fields.

My password contained special characters, and character restoration/password changing said "Wrong password or authentication rejected"/"Invalid username or password".

OK, after I reset a password, I received one only with letters and digits. And password change succeeded. But I changed password back again to containing special chars, aaand...

...character restoration says "Wrong password or authentication rejected" again.

Bonus: you've got typo in links:

  1. https://testpage.elysium-project.org/main/changepass.html on the English main page,
  2. https://elysium-project.org/ru/main/restorepass.html - on the Russian one.

Good luck, developers! I believe - you'll easily fix all of these.

Share this post


Link to post
Share on other sites

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now

×