4 ms·
It depends upon where you are validating email input at. For the initial email input, your logic works fine. Once it is applied downstream in a process, it be
by WindyLakeReturn 5y ago
It depends upon where you are validating email input at.
For the initial email input, your logic works fine. Once it is applied downstream in a process, it begins to get messy. Someone might do an incorrect email validation that happens to block emails that you have already accepted or which you are importing from a valid source. Someone has already given the example of a login field not allowing them to use the email they signed up with. If such upgrades occur later in a projects life cycle, not only might you have to spend developer's time, you may also have a production outage.
Personally, I suggest using some, even if imperfect, validation when gathering the email initially (for the reasons you point out) and then not validating that information any further.
- paulmd 5y agoI actually run into this all the time with passwords using a password manager. Lots of places will accept the creation of a password that's long/complex/etc but then when you actually try to log in with it it won't accept a long password, won't accept certain characters, will silently truncate it and throw an invalid password error, etc. Sometimes disabling Javascript will fix it, sometimes not. I occasionally have resort to using "I forgot my password" until I figure out what the actual underlying requirements of the passwords are.
- lcuff 5y agoYup! Same thing with the ridiculous verify-my-identify questions. One I encounter all the time is the local community college, which let me use spaces in my answers on creation, but not at entry time. Grrrr.
- feanaro 5y agoI don't encounter this very often myself. So far the only place I've seen this is Paypal. facepalm
- CodeMage 5y agoAs a user, I got burned by that several times. Now, when I create a new account somewhere, the first thing I do is log out and try to log back in.
- zerd 5y agoEtrade lets you create 32 character password, but if you enable 2FA you suddenly can't login because apparently they concatenate them together and then check the length. So make sure your password is max 26 characters. (they might've fixed this but I haven't tried).
- sbierwagen 5y agoLike GP mentioned, Etrade also does the thing where it accepts the . character on password creation, but not login. That was fun to figure out.
- hsbauauvhabzb 5y agoCurious, can you login with 26 characters and your MFA seed to bypass MFA entirely?
- fomine3 5y ago<input type="password" maxlength="xx"> must be illegal. It can't be noticed whether is input truncated.
- zxcvbn4038 5y agoThat happens too often! A lot of places where I try to use a really long password will silently truncate it, but different forms will truncate at different lengths, so what might work for registration might not work for login or changing the password later. I’m always suspicious when sites cap passwords at < 32 characters, that almost always means it’s being stored in a reversesble format someplace - maybe encrypted, maybe obfuscated, or maybe not either (banks). The sites I really trust don’t care how long your password is because their hash size is fixed. The only real length consideration might be that if a bunch of people send obnoxiously long passwords at the same time and they are using bcryprt or scrypt it might stress the server’s cpu, so they might put an upper limit to prevent that.
- citycide 5y agoI ran into this with Sony's PlayStation site. I generated a passphrase that the registration form allowed but from then on I was unable to access my account. I went through the same trial as you and found that they were truncating the password to something like 16 characters. That was just this past year, so I'm pretty sure it's still that way.
- novok 5y agoI've run into this with labcorp. Their desktop webapp takes subdomain emails, but their mobile iOS health webpage login thinks a subdomain email is invalid and disables the login button. They also don't let you change your account email so you can never really fix this issue properly.