From d5c6381d907cc03f6fc2ba2d894e32f9ff827183 Mon Sep 17 00:00:00 2001 From: Joel Lee Date: Tue, 9 Jan 2024 10:28:37 +0800 Subject: [PATCH] feat: update password strength requirements (#20251) Update passwords.mdx --- apps/docs/pages/guides/auth/passwords.mdx | 4 ++++ 1 file changed, 4 insertions(+) diff --git a/apps/docs/pages/guides/auth/passwords.mdx b/apps/docs/pages/guides/auth/passwords.mdx index ec5b4705ccc..41d85695f4b 100644 --- a/apps/docs/pages/guides/auth/passwords.mdx +++ b/apps/docs/pages/guides/auth/passwords.mdx @@ -150,6 +150,10 @@ Supabase Auth uses [bcrypt](https://en.wikipedia.org/wiki/Bcrypt), a strong pass The hash is stored in the `encrypted_password` column of the `auth.users` table. The column's name is a misnomer (cryptographic hashing is not encryption), but is kept for backward compatibility. +### How will strengthened password requirements affect current users? + +Existing users can still sign in with their current password even if it doesn't meet the new, strengthened password requirements. However, if their password falls short of these updated standards, they will encounter a `WeakPasswordError` during the `signInWithPassword` process, explaining why it's considered weak. This change is also applicable to new users and existing users changing their passwords, ensuring everyone adheres to the enhanced security standards. + export const Page = ({ children }) => export default Page