‹ BackHN Continuity

Thread

<input type="password" maxlength="20"> prevents me from logging into Vanguard

66 points · 99 comments · tanin

  1. bootlooped · · focus · HN ↗
    My biggest question here is are they not just feeding the input into a hash function, why can&#x27;t it be longer than 20 characters?
    1. hombre_fatal · · focus · HN ↗
      It&#x27;s a good habit to always create an upper bound on things (input max length, queue size, etc).

      The person who wrote it just came up with 20 in the moment and forgot to go check, something everyone has done a hundred times.

      I&#x27;ve probably never worked on a single system where the html validation, http server validation, and database constraint were synchronized on username max length. You choose a placeholder, an even number between 10 and 16, then forget to ever check.

Open on Hacker News to reply ↗

Unofficial Hacker News client; not affiliated with Y Combinator.