4 ms·
There is a subtle valid use-case. On "change your password" screens, you don't want the second "confirm password" field to be pastle-able to stop this scenario
by jomkr 9y ago
There is a subtle valid use-case.
On "change your password" screens, you don't want the second "confirm password" field to be pastle-able to stop this scenario.
1) User tries to type "mypassword" but enters "mypasswor" instead.
2) User copy-pastes "mypasswor" into "confirm password field"
3) User hits "submit".
Now when the user tries to login with "mypassword" it fails.
- teej 9y agoCan't the user just reset their password again?
- city41 9y agoThat is true, and a valid point. But preventing pasting here will still discourage the use of password managers. I ask my password manager for a new, very long, and very difficult to type password. I paste it twice. It's a shame that password managers are mostly used by tech savvy people, as they are probably the most secure way to deal with passwords we've come up with so far.
- PUSH_AX 9y agoIf the input field is of type password the browser won't allow you to copy from it anyway. Pasting should still be allowed.
- crazygringo 9y agoBut you can't copy from password fields, so that won't actually work. When changing your password, if you're pasting at all, it's from another (presumably correct) source -- so pasting is fine, whether once or twice.
- deleted 9y ago[deleted]
- jeffhuys 9y agoI thought it's not possible to COPY from a password field?
- thechriswalker 9y agoI think the use cases there is more accurately, if the user doesn't paste into the first box AND copies the content, don't let them paste into the second. I would paste into both boxes and resort to developer tools if I am not allowed.
- dkonofalski 9y agoThat's fine. They can still reset their password and type it in properly. It's a minor inconvenience for the really, really rare use case where this happens. For one, you can't copy from a password field so it would have to be typed and copied from an external source. As long as it doesn't leave them in a locked-out state, I see no issues with this.