Re: Password Strength Check
| From: | Geoff Coffey | Date: | Tue, 02 Jan 2001 20:19:46 +0000 |
| Subject: | Re: Password Strength Check | ||
| References: | 1 | Groups: | php.general |
| Request: | Send a blank email to php-general+get-32331@lists.php.net to get a copy of this message | ||
on 12/31/00 12:21 PM, Michael Conley at mconley@nsiis.com wrote:
> I want to require that a user choose a password that contains at least 6
> characters, at least 2 of which must be letters (upper of lower case) and 2
> must be non-characters (numbers or special characters). I'm having a tough
> time figuring out how to do this. I can use substr_count to check for the
> number of occurences of a character, but I don't want to check for each
> letter, each number and each special character for this check. Is there
> anything that can be used like the ereg option that use [0-9] and [a-zA-Z]?
> I originally was using ereg, but couldn't figure out how to make that do
> what I wanted as I don't care what order the letter, number and special
> characters are in within the password.
>
> Bottom line- if someone types in what they want to change their password to,
> how can I check it to ensure that it meets the requirements above?
You can just use regular expressions with multiple checks...like this:
"[A-z].*[A-z]" <= checks for at least two alpha chars
"[^A-z].*[^A-z]" <= checks for at least two non-alpha chars
If both patterns match the password, it meets your criteria.
Geoff