MDL-61694 core: Add callback to allow additional password check.
The standard password validation does some basic strength checks, but there are a number of other ways to validate a password, such as checking that it doesn't contain common words. Adding a plugin hook here allows us to keep up with changes in best practice in this area as it evolves over time.
This commit is contained in:
+30
-24
@@ -4745,32 +4745,38 @@ function get_complete_user_data($field, $value, $mnethostid = null) {
|
||||
function check_password_policy($password, &$errmsg) {
|
||||
global $CFG;
|
||||
|
||||
if (empty($CFG->passwordpolicy)) {
|
||||
return true;
|
||||
if (!empty($CFG->passwordpolicy)) {
|
||||
$errmsg = '';
|
||||
if (core_text::strlen($password) < $CFG->minpasswordlength) {
|
||||
$errmsg .= '<div>'. get_string('errorminpasswordlength', 'auth', $CFG->minpasswordlength) .'</div>';
|
||||
}
|
||||
if (preg_match_all('/[[:digit:]]/u', $password, $matches) < $CFG->minpassworddigits) {
|
||||
$errmsg .= '<div>'. get_string('errorminpassworddigits', 'auth', $CFG->minpassworddigits) .'</div>';
|
||||
}
|
||||
if (preg_match_all('/[[:lower:]]/u', $password, $matches) < $CFG->minpasswordlower) {
|
||||
$errmsg .= '<div>'. get_string('errorminpasswordlower', 'auth', $CFG->minpasswordlower) .'</div>';
|
||||
}
|
||||
if (preg_match_all('/[[:upper:]]/u', $password, $matches) < $CFG->minpasswordupper) {
|
||||
$errmsg .= '<div>'. get_string('errorminpasswordupper', 'auth', $CFG->minpasswordupper) .'</div>';
|
||||
}
|
||||
if (preg_match_all('/[^[:upper:][:lower:][:digit:]]/u', $password, $matches) < $CFG->minpasswordnonalphanum) {
|
||||
$errmsg .= '<div>'. get_string('errorminpasswordnonalphanum', 'auth', $CFG->minpasswordnonalphanum) .'</div>';
|
||||
}
|
||||
if (!check_consecutive_identical_characters($password, $CFG->maxconsecutiveidentchars)) {
|
||||
$errmsg .= '<div>'. get_string('errormaxconsecutiveidentchars', 'auth', $CFG->maxconsecutiveidentchars) .'</div>';
|
||||
}
|
||||
}
|
||||
|
||||
$errmsg = '';
|
||||
if (core_text::strlen($password) < $CFG->minpasswordlength) {
|
||||
$errmsg .= '<div>'. get_string('errorminpasswordlength', 'auth', $CFG->minpasswordlength) .'</div>';
|
||||
|
||||
}
|
||||
if (preg_match_all('/[[:digit:]]/u', $password, $matches) < $CFG->minpassworddigits) {
|
||||
$errmsg .= '<div>'. get_string('errorminpassworddigits', 'auth', $CFG->minpassworddigits) .'</div>';
|
||||
|
||||
}
|
||||
if (preg_match_all('/[[:lower:]]/u', $password, $matches) < $CFG->minpasswordlower) {
|
||||
$errmsg .= '<div>'. get_string('errorminpasswordlower', 'auth', $CFG->minpasswordlower) .'</div>';
|
||||
|
||||
}
|
||||
if (preg_match_all('/[[:upper:]]/u', $password, $matches) < $CFG->minpasswordupper) {
|
||||
$errmsg .= '<div>'. get_string('errorminpasswordupper', 'auth', $CFG->minpasswordupper) .'</div>';
|
||||
|
||||
}
|
||||
if (preg_match_all('/[^[:upper:][:lower:][:digit:]]/u', $password, $matches) < $CFG->minpasswordnonalphanum) {
|
||||
$errmsg .= '<div>'. get_string('errorminpasswordnonalphanum', 'auth', $CFG->minpasswordnonalphanum) .'</div>';
|
||||
}
|
||||
if (!check_consecutive_identical_characters($password, $CFG->maxconsecutiveidentchars)) {
|
||||
$errmsg .= '<div>'. get_string('errormaxconsecutiveidentchars', 'auth', $CFG->maxconsecutiveidentchars) .'</div>';
|
||||
// Fire any additional password policy functions from plugins.
|
||||
// Plugin functions should output an error message string or empty string for success.
|
||||
$pluginsfunction = get_plugins_with_function('check_password_policy');
|
||||
foreach ($pluginsfunction as $plugintype => $plugins) {
|
||||
foreach ($plugins as $pluginfunction) {
|
||||
$pluginerr = $pluginfunction($password);
|
||||
if ($pluginerr) {
|
||||
$errmsg .= '<div>'. $pluginerr .'</div>';
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
if ($errmsg == '') {
|
||||
|
||||
Reference in New Issue
Block a user