Welcome Guest, Not a member yet? Register   Sign In
Question new form validation rule
#8

(10-22-2018, 12:56 PM)kilishan Wrote: Looking at this, I think it would be great to have - but as a third-party addin, rather than in core. Part being that it relies on a third-party service and also, while they've done a good job a trying to minimize the security risk, there is still some that a developer/company would need to evaluate for their own uses.

That said, I think the concept of adding a wrapper to that and making it a validation rule is awesome, and something I'd definitely considering using. I've already got a similar password check built into the auth library that I'm working on, though the dataset is much smaller (only 600,000 passwords) and not kept up to date.


I understand your argument that because it is a third-party service building it in the core might not be the right location for it.
2nd part of it I wouldn't 100% agree with "there is still some that a developer/company would need to evaluate for their own uses", because they still have the option to use it or not by adding the validation rule or not. If they don't add the validation rule I don't see how this would be a possible security riskĀ (You could also add a warning in docs that it uses a third-party service).

Currently seems mixed, making a PR for core or not. Not sure what to do yet.
Reply


Messages In This Thread
Question new form validation rule - by glennm - 10-22-2018, 12:42 AM
RE: Question new form validation rule - by glennm - 10-22-2018, 01:31 AM
RE: Question new form validation rule - by glennm - 10-22-2018, 12:42 PM
RE: Question new form validation rule - by glennm - 10-22-2018, 02:00 PM
RE: Question new form validation rule - by glennm - 10-23-2018, 11:05 AM



Theme © iAndrew 2016 - Forum software by © MyBB