diff --git a/Makefile b/Makefile index bd2a837..b8e9ddf 100644 --- a/Makefile +++ b/Makefile @@ -1,5 +1,5 @@ REPO=npenkov/docker-ldap-passwd-webui -VER=1.1 +VER=1.2 .PHONY: all build push diff --git a/README.md b/README.md index 2f6faca..bb0f968 100644 --- a/README.md +++ b/README.md @@ -38,6 +38,8 @@ docker run -d -p 8080:8080 --name ldap-passwd-webui \ -e LPW_SSL_SKIP_VERIFY="true" \ -e LPW_USER_DN="uid=%s,ou=people,dc=example,dc=org" \ -e LPW_USER_BASE="ou=people,dc=example,dc=org" \ + -e LPW_PATTERN='.{8,}' \ + -e LPW_PATTERN_INFO="Password must be at least 8 characters long." \ npenkov/docker-ldap-passwd-webui:latest ``` diff --git a/app/util.go b/app/util.go index 187ef06..9c55e5d 100644 --- a/app/util.go +++ b/app/util.go @@ -9,6 +9,14 @@ func getTitle() string { return envStr("LPW_TITLE", "Change your password on example.org") } +func getPattern() string { + return envStr("LPW_PATTERN", ".{8,}") +} + +func getPatternInfo() string { + return envStr("LPW_PATTERN_INFO", "Password must be at least 8 characters long.") +} + func envStr(key, defaultValue string) string { val := os.Getenv(key) if val != "" { diff --git a/app/web.go b/app/web.go index 3822781..cfce6d4 100644 --- a/app/web.go +++ b/app/web.go @@ -48,10 +48,12 @@ func (h *RegexpHandler) ServeHTTP(w http.ResponseWriter, r *http.Request) { } type pageData struct { - Title string - Username string - Alerts map[string]string - CaptchaId string + Title string + Pattern string + PatternInfo string + Username string + Alerts map[string]string + CaptchaId string } // ServeAssets : Serves the static assets @@ -61,7 +63,7 @@ func ServeAssets(w http.ResponseWriter, req *http.Request) { // ServeIndex : Serves index page on GET request func ServeIndex(w http.ResponseWriter, req *http.Request) { - p := &pageData{Title: getTitle(), CaptchaId: captcha.New()} + p := &pageData{Title: getTitle(), CaptchaId: captcha.New(), Pattern: getPattern(), PatternInfo: getPatternInfo()} t, e := template.ParseFiles(path.Join("templates", "index.html")) if e != nil { log.Printf("Error parsing file %v\n", e) @@ -102,6 +104,10 @@ func ChangePassword(w http.ResponseWriter, req *http.Request) { alerts["error"] = "New and confirmation passwords does not match. " } + if m, _ := regexp.MatchString(getPattern(), newPassword[0]); !m { + alerts["error"] = alerts["error"] + fmt.Sprintf("%s", getPatternInfo()) + } + if len(captchaID) < 1 || captchaID[0] == "" || len(captchaSolution) < 1 || captchaSolution[0] == "" || !captcha.VerifyString(captchaID[0], captchaSolution[0]) { diff --git a/templates/index.html b/templates/index.html index 4ea5e76..f7708c4 100644 --- a/templates/index.html +++ b/templates/index.html @@ -54,12 +54,12 @@ + pattern="{{.Pattern}}" x-moz-errormessage="{{.PatternInfo}}" required> - + pattern="{{.Pattern}}" x-moz-errormessage="{{.PatternInfo}}" required> +
{{.PatternInfo}}
Type the numbers you see in the picture below: