-
Notifications
You must be signed in to change notification settings - Fork 0
/
password-sim.js
53 lines (40 loc) · 1.85 KB
/
password-sim.js
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
//
// Install:
// $ npm install wt -g
// $ wt init <youremail>
// $ wt create password-sim.js --name password-similarity \
//
var distance = require("fast-levenshtein");
module.exports = function (ctx, callback) {
// Empirical number to prevent a lot of false positives
var MAX_SIMILARITY = 0.7;
// Checks and returns the similarity ration of 2 strings using the `distance` algorithm
var similarity_ratio = function(a, b) {
if (!a || !b || !a.length || !b.length) return 0;
if (a === b) return 1;
var d = distance.get(a.toLowerCase(), b.toLowerCase());
var longest = Math.max(a.length, b.length)
return (longest-d)/longest
};
// Require only safe params. Can be extended to require more parameters
var safe_params = ['password', 'username', 'email'];
for (var param in safe_params)
if (!ctx.data[safe_params[param]])
return callback(new Error('The `' + safe_params[param] + '` parameter must be provided.'));
var checked_params = safe_params.slice(1);
for (var attribute in checked_params) {
var value = ctx.data[checked_params[attribute]];
var password = ctx.data['password'];
if (value) {
var value_trimmed = value.trim();
if ((value.indexOf(password) > -1) || (password.indexOf(value) > -1) || (similarity_ratio(password, value_trimmed) > MAX_SIMILARITY)) {
return callback(null, { verdict: false, detail: "The password is too similar to the `" + checked_params[attribute] + '`'});
}
}
else {
return callback(new Error('The `' + safe_params[param] + '` parameter value is missing.'));
}
}
// Nothing similar with that password
return callback(null, { verdict: true});
};