All tasksBeginner+100 XP2–3 hoursOpen
Require stronger passwords on signup
Signup accepts any non-empty password, even "1". Add basic strength rules in src/validation.js so weak passwords are rejected with a clear message.
What you'll learn
Extend an existing validator and keep the test suite green when rules change
Acceptance criteria
- validatePassword rejects passwords shorter than 8 characters
- Password must contain at least one letter and one number
- The error message says exactly which rule failed
- New tests cover valid and invalid passwords in test/validation.test.js
- Existing tests that use weak passwords are updated so npm test passes
Contribution rules
- Work on a branch named
task-1-… - Your PR description must include
Closes #1 - Open the PR from the GitHub account you signed in with
- A maintainer must approve and merge it