Password strength problem
-
Hello dear Masteriyo
When i enable the password strength in Masteriyo, the sign up button in Masteriyo account page stops working. I’m using Masteriyo 2.3.3.
-
This topic was modified 3 weeks, 3 days ago by
derlehre.
-
This topic was modified 3 weeks, 3 days ago by
-
Hi @derlehre ,
Thanks for the detailed report. We tracked this down and can confirm what’s happening.
When Password Strength is enabled, the signup form checks the password against the configured requirements, including its length and character requirements, before allowing the form to submit.
If the password doesn’t meet one of these requirements most commonly, if it exceeds the Maximum Length setting the form currently fails to submit without showing any error. The strength indicator may still show “Strong,” which makes the issue even more confusing.
That’s on us. The form should clearly indicate which requirement is failing instead of silently preventing submission.
For now, you can get the signup form working by going to:
Masteriyo → Settings → Advanced → Password Strength → Max Length
You can either increase the maximum length or use a shorter password while testing.
In the future, we’re improving this behaviour so the form clearly displays the specific password requirement that isn’t met, rather than failing silently.
We appreciate you bringing this to our attention, and thanks for your patience while we work on improving this experience.
-
This reply was modified 3 weeks, 2 days ago by
sauravkhanal.
@sauravkhanal Hello dear
The password check has Minimum and Maximum limit. I write the password and it was more than the minimum and less than the maximum. Again it was not letting the sign up/register button to work and didn’t show any error. When i disable the password check, the register button starts working correctly.
A few important thing for the next update:
- Password check problem, not letting the sign up register button to work.
- there is no icon of eye there so that the users see the password they are writing.
- When the registration form is filled by the user and forgets to click on the checkbox of the accept privacy-policy, above the registration page, it’s showing to the user that he didn’t check that box. But unfortunately, something else also happens. The second field of the password will be cleared. So the users click on the checkbox and then click on register or sign up and then he gets the message that he didn’t write the second password field.
- after filling the form, when the students click on register/ sign up button, it’s showing nothing to them and they should wait until the page redirect them to their masteriyo account page. Sometimes the redirection can take some time according to the internet and also the server that is used. So it might take a little bit longer time to redirect the student to the account page. And something else happens, Because they don’t wait until they be redirected, The problem of this happens that they will be registered, but because they don’t wait until redirection, they click again on the sign up button, they will get the message that There is already an account eith this username or email. So adding a small animation such as something which is showing them loading or redirecting, showing them a loop can be very helpful because it denies it avoids them to click multiple times.
Hi @derlehre,
Thanks for testing this further. Your follow-up actually helped us identify another part of the issue. I’ve reproduced the silent validation behavior, and we’ve logged it as a bug.
Length isn’t the only rule involved. Under Masteriyo → Settings → Advanced → Password Strength, there’s also a Strength setting:
- Low requires an uppercase letter.
- Medium requires an uppercase letter and a number.
- High also requires a special character.
The checklist turns satisfied rules green, but it doesn’t clearly indicate when a rule has failed, so it’s easy to miss what’s preventing the form from submitting.
There’s another possibility if your Strength setting is already Very Low: a leading or trailing space can sometimes be added when pasting a password or using a password manager. The checklist ignores that, while the actual validation still counts it. Retyping the password manually would rule this out.
Either way, the issue is on our side. The form should clearly tell you which validation rule has failed instead of simply doing nothing. That’s the behavior we’re working to fix.
For now, you can leave the password-strength check disabled as you have it, or set Strength to Very Low and increase the Maximum length if needed.
We’ve also logged your other three points:
- The password visibility (eye) icon
- Confirm Password being cleared while Password is restored
- Adding a loading state to prevent double submissions
We don’t have a release date to promise yet, but the silent-validation issue is the priority.
Thanks again for testing this further.
-
This reply was modified 3 weeks, 2 days ago by
You must be logged in to reply to this topic.