Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Passwords longer than 15 characters now allowed #787

Closed
reni3008 opened this issue Nov 8, 2023 · 6 comments
Closed

Passwords longer than 15 characters now allowed #787

reni3008 opened this issue Nov 8, 2023 · 6 comments

Comments

@reni3008
Copy link

reni3008 commented Nov 8, 2023

Bricklink now allows passwords with more than 15 characters, but Brickstore only accept max 15 characters

@rgriebl
Copy link
Owner

rgriebl commented Nov 9, 2023

The FAQ says:
Will BrickLink be adding other account security like two-factor authentication and longer passwords?

At the moment, BrickLink hasn't updated our password requirements and does not support two-factor authentication. We'll continue to increase security on our platform and will communicate about any new security features as they become available.

So where do get that information from?
BTW: You could always type more than 15 characters into that password fields on BL, but only the first 15 are used.

@froqzy
Copy link

froqzy commented Nov 9, 2023

I had the same experience. I used a password > 15 chars on Bricklink yesterday and updated it in Brickstore. As a result Brickstore couldn't retrieve info from our Bricklink store anymore. If both (Bricklink and Brickstore) would have been truncated at 15 chars there wouldn't have been a problem. So I guess Bricklink does allow for more than 15 chars that are used. Changed the password back to 15 chars on Bricklink and both worked fine again. Not proof but it might be an undocumented change. Wouldn't be a first for Bricklink ;-)

@rgriebl
Copy link
Owner

rgriebl commented Nov 9, 2023

It seems that > 15 are only possible via the new pw-reset mechanism the?. The classic way of changing your PW in the account info (*) is still limited to 15 chars (you cannot type in more)
So I'm not even sure how you managed to switch back from a > 15 char PW, as you couldn't even type that into the "Current Password" field

(*) https://www.bricklink.com/pref_general.asp?rD=Y

@froqzy
Copy link

froqzy commented Nov 9, 2023

That's very well possible, since I originally added a >15 char pwd during the pwd-reset mechanism. I switched back using the same pwd-reset mechanism. Oddly enough you can use those links more than once...
So probably this isn't an issue for Brickstore at all but more like a one-off thing.

@rgriebl
Copy link
Owner

rgriebl commented Nov 9, 2023

@rgriebl
Copy link
Owner

rgriebl commented Nov 13, 2023

Closing, as the 15 char limit is still in place on BL.

That being said, you can enter a longer password in BrickStore and it will use it (that warning you get in the settings dalog is just FYI).

So what you have been running into is this: you reset your PW to something > 15 chars and the reset procedure let you input that. It did however only save the first 15 chars, so the "full" password in BrickStore didn't match.
If you had set the password to only the first 15 chars in BrickStore, it would have worked.

Ergo: that BrickStore warning about >15 char passwords was and still is doing its job perfectly fine

@rgriebl rgriebl closed this as completed Nov 13, 2023
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

3 participants