#1 2022-01-18 13:02:28

testacc
Player
Posts: 2

Hidden password length limit

I recently signed up to the website for a few games but have hit an issue with my account where my username and password weren't recognised.  As there seemed to be no way to reset the password and it was only a new account, I simply created a new one and tried again, but then ran into the same issue.  I use a password manager, so mistyping the password isn't the issue.

On a hunch, I then created a third account, this one, with a 28 character password, logged out and was then able to successfully log in again.  I then created a fourth account with a 128 character password, which the website accepted.   I then logged out, but as predicted I was unable to log in again.

From this, it seems that there is a hidden password length limit of somewhere between 28 and 128 characters.  Logging in with a password longer than this succeeds, but password recorded by the site is not the same as the one you typed in, leaving you unable to log in again.  This should be looked into and the limit made more explicit at the login screen.  Could I also ask that you reset the password for my original account, Xinthroni?

Offline

#2 2022-01-18 15:24:09

jwrober
Administrator
From: San Antonio, TX
Posts: 87

Re: Hidden password length limit

Thanks for reporting this. It has been logged and we will have a look.

Offline

#3 2022-01-18 15:26:15

wieder
Administrator
Posts: 1,863

Re: Hidden password length limit

Hi!

Can you receive the new password to the mail address you have entered on the web site?

Offline

#4 2022-01-18 15:46:37

louis94
Administrator
Posts: 66

Re: Hidden password length limit

Hi! Just checked. The password field has a maximum length of 60 characters and the browser prevents from typing more. The login field, on the other hand, will happily accept any password length.

I'm not sure how to technically fix this. There's a hard limit at 128 characters from Freeciv, so can't allow anything beyond that.

Offline

#5 2022-01-18 18:04:29

testacc
Player
Posts: 2

Re: Hidden password length limit

wieder wrote:

Hi!

Can you receive the new password to the mail address you have entered on the web site?

Yes please.

Offline

#6 2022-01-18 18:58:32

Xinthroni
Player
Posts: 2

Re: Hidden password length limit

wieder wrote:

Hi!

Can you receive the new password to the mail address you have entered on the web site?

Actually no need to reset.  I was able to get in just by truncating my password to 60 characters.

Offline

Board footer

Powered by FluxBB