mirror of
https://github.com/Sea-Haven-Industries/shoc-backend.git
synced 2026-09-30 03:43:11 +00:00
Both hosts now apply the same Identity password rule: at least 6 characters with one uppercase letter, one number and one special character. Change password requires an authenticated caller, verifies the current password before evaluating the new one, and reports a policy rejection separately from a wrong current password.
27 lines
955 B
C#
27 lines
955 B
C#
using Microsoft.AspNetCore.Identity;
|
|
|
|
namespace Data.SeaHavenIndustries
|
|
{
|
|
/// <summary>
|
|
/// The single password rule for every surface that sets a password: at least
|
|
/// six characters with one uppercase letter, one number, and one special
|
|
/// character. Lowercase letters are deliberately not required so the server
|
|
/// accepts exactly what the four-item checklist in the web app marks as met.
|
|
/// </summary>
|
|
public static class IdentityPasswordPolicy
|
|
{
|
|
public const int MinimumLength = 6;
|
|
|
|
public static void Apply(PasswordOptions options)
|
|
{
|
|
ArgumentNullException.ThrowIfNull(options);
|
|
|
|
options.RequiredLength = MinimumLength;
|
|
options.RequireUppercase = true;
|
|
options.RequireDigit = true;
|
|
options.RequireNonAlphanumeric = true;
|
|
options.RequireLowercase = false;
|
|
options.RequiredUniqueChars = 1;
|
|
}
|
|
}
|
|
}
|