Security News
Maven Central Adds Sigstore Signature Validation
Maven Central now validates Sigstore signatures, making it easier for developers to verify the provenance of Java packages.
angular-zxcvbn
Advanced tools
This is a simple directive for the zxcvbn library.
Install with bower:
bower install zxcvbn angular-zxcvbn
Include the following javascript source files:
<script src='/bower_components/zxcvbn/dist/zxcvbn.js'></script>
<script src='/bower_components/angular-zxcvbn/dist/angular-zxcvbn.js'></script>
Add zxcvbn
as an angular dependency. E.G. If your module is called myApp
then you would do:
angular.module('myApp', ['zxcvbn']);
Live plunker: http://plnkr.co/edit/COTgky?p=preview
The main way to use the directive is as an attribute alongside the ng-model
attribute:
<input type='password' ng-model='userPassword' zxcvbn="passwordStrength">
This will set $scope.passwordStrength
to the result of calling the zxcvbn function on
$scope.userPassword
.
The directive has an optional attribute of zx-extras
. This takes either an array
or an [angular form object](https://docs.angularjs
.org/api/ng/type/form.FormController), which will be passed as the optional argument to the zxcvbn
call.
The optional argument is an array of strings that zxcvbn will treat as an extra dictionary. This can be whatever list of strings you like, but is meant for user inputs from other fields of the form, like name and email. That way a password that includes a user's personal information can be heavily penalized. This list is also good for site-specific vocabulary — Acme Brick Co. might want to include ['acme', 'brick', 'acmebrick', etc]. -- zxcvbn readme.md
Example:
<form name="myForm">
<input type="email" ng-model="email" name="emailAddress">
<input type="text" ng-model="username" name="username">
<input type="password" ng-model="password" name="password" zxcvbn="passwordStrength" zx-extras="myForm">
<input type="password" ng-model="confirmPassword" name="confirmPassword">
</form>
We pass zx-extras
the value myForm
, which is the value of the name
attribute of the parent <form>
element.
angular-zxcvbn
will look at all <input>
elements with name
and ng-model
attributes inside the <form>
element - ignoring
fields with 'password' in their name. Found fields are then used as the extras parameter in the zxcvbn call.
Note: if you do not wish to pass in a form object, you can also pass a scope variable that is an array of strings.
If you are using the AngularJS form directive you may also want to have the password field marked as invalid when below a certain score.
This can be done by passing a zx-min-score
attribute, which takes an integer between 0 and 4 inclusive. For example: zx-min-score="2"
would invalidate passwords with scores 0 or 1.
<input type="password" ng-model="password" name="password" zxcvbn="passwordStrength" zx-min-score="2">
You can also pass an interpolated scope value: zx-min-score="{{ minScore }}"
You can use the directive as an element. The element takes 3 attributes:
password
required - the password that you want to be tested (scope variable).extras
optional - an array of strings that zxcvbn will use to get a better "crack time" estimate. Here you would normally have other form fields such as name, email address, username...data
optional - a scope object that will contain the returned data from the zxcvbn call.<zxcvbn password='passwordVar' extras='extrasArray' data='zxcvbnData'></zxcvbn>
Live plunker: http://plnkr.co/edit/CYtyRA?p=preview
Refer to the CHANGELOG file.
© 2014, Jose Luis Rivas, me@ghostbar.co.
2015, James Clark, james.clark92@hotmail.co.uk
2016, Giovanni Pellerano, giovanni.pellerano@evilaliv3.org
The files are licensed under the MIT terms.
FAQs
Angular directive for the library zxcvbn
The npm package angular-zxcvbn receives a total of 0 weekly downloads. As such, angular-zxcvbn popularity was classified as not popular.
We found that angular-zxcvbn demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Security News
Maven Central now validates Sigstore signatures, making it easier for developers to verify the provenance of Java packages.
Security News
CISOs are racing to adopt AI for cybersecurity, but hurdles in budgets and governance may leave some falling behind in the fight against cyber threats.
Research
Security News
Socket researchers uncovered a backdoored typosquat of BoltDB in the Go ecosystem, exploiting Go Module Proxy caching to persist undetected for years.