feat: add auth form validation schemas and password strength utility

This commit is contained in:
2026-04-26 01:12:03 +08:00
parent 4fc4b070dc
commit 9588733278
2 changed files with 142 additions and 0 deletions
+93
View File
@@ -0,0 +1,93 @@
export type StrengthLevel = "weak" | "fair" | "good" | "strong" | "excellent"
export interface PasswordStrength {
score: number
level: StrengthLevel
feedback: string[]
}
const COMMON_PATTERNS = [
"password",
"123456",
"12345678",
"qwerty",
"abc123",
"monkey",
"master",
"dragon",
"login",
"admin",
"letmein",
"welcome",
"shadow",
"sunshine",
"trustno1",
"iloveyou",
]
export function checkPasswordStrength(password: string): PasswordStrength {
if (!password) {
return { score: 0, level: "weak", feedback: ["Enter a password"] }
}
let score = 0
const feedback: string[] = []
// Length scoring
if (password.length >= 10) score += 20
else feedback.push("Use at least 10 characters")
if (password.length >= 14) score += 10
else if (password.length >= 10) feedback.push("Use 14+ characters for extra security")
if (password.length >= 18) score += 10
// Character variety
const hasUpper = /[A-Z]/.test(password)
const hasLower = /[a-z]/.test(password)
const hasNumber = /[0-9]/.test(password)
const hasSpecial = /[^A-Za-z0-9]/.test(password)
if (hasUpper) score += 15
else feedback.push("Add an uppercase letter")
if (hasLower) score += 15
else feedback.push("Add a lowercase letter")
if (hasNumber) score += 15
else feedback.push("Add a number")
if (hasSpecial) score += 15
else feedback.push("Add a special character (!@#$%^&*)")
// Common pattern check
const lower = password.toLowerCase()
const isCommon = COMMON_PATTERNS.some((p) => lower.includes(p))
if (!isCommon) score += 10
else feedback.push("Avoid common passwords")
// Repeated characters
const hasRepeated = /(.)\1{2,}/.test(password)
if (!hasRepeated) score += 5
else feedback.push("Avoid repeated characters")
// Mixed positions (not all numbers at end, not all caps at start)
const endsWithNumbers = /[0-9]+$/.test(password) && !/[0-9]/.test(password.slice(0, -3))
const startsWithCaps = /^[A-Z]{3,}/.test(password) && !/[A-Z]/.test(password.slice(3))
if (!endsWithNumbers && !startsWithCaps) score += 5
// Determine level
let level: StrengthLevel
if (score <= 20) level = "weak"
else if (score <= 40) level = "fair"
else if (score <= 60) level = "good"
else if (score <= 80) level = "strong"
else level = "excellent"
// If all checks pass, clear feedback
if (feedback.length === 0) {
feedback.push("Great password!")
}
return { score, level, feedback }
}
+49
View File
@@ -0,0 +1,49 @@
import { z } from "zod"
export const loginEmailSchema = z.object({
email: z.string().email("Please enter a valid email address"),
})
export const loginSchema = z.object({
email: z.string().email("Please enter a valid email address"),
password: z.string().min(1, "Password is required"),
})
export const signupSchema = z.object({
name: z
.string()
.min(1, "Name is required")
.max(100, "Name must be 100 characters or less"),
email: z.string().email("Please enter a valid email address"),
password: z
.string()
.min(10, "Password must be at least 10 characters"),
})
export const otpSchema = z.object({
otp: z.string().length(6, "OTP must be exactly 6 digits"),
})
export const forgotPasswordSchema = z.object({
email: z.string().email("Please enter a valid email address"),
})
export const resetPasswordSchema = z
.object({
otp: z.string().length(6, "OTP must be exactly 6 digits"),
newPassword: z
.string()
.min(10, "Password must be at least 10 characters"),
confirmPassword: z.string().min(1, "Please confirm your password"),
})
.refine((data) => data.newPassword === data.confirmPassword, {
message: "Passwords do not match",
path: ["confirmPassword"],
})
export type LoginEmailInput = z.infer<typeof loginEmailSchema>
export type LoginInput = z.infer<typeof loginSchema>
export type SignupInput = z.infer<typeof signupSchema>
export type OtpInput = z.infer<typeof otpSchema>
export type ForgotPasswordInput = z.infer<typeof forgotPasswordSchema>
export type ResetPasswordInput = z.infer<typeof resetPasswordSchema>