20 lines
944 B
TypeScript
20 lines
944 B
TypeScript
import { ConfigService } from '@nestjs/config';
|
|
import { ApiError } from '../errors/api-error';
|
|
import { ERROR_CODES } from '../errors/error-codes';
|
|
|
|
export function validatePassword(password: string, config: ConfigService): void {
|
|
const minLen = config.get<number>('PASSWORD_MIN_LENGTH', 12);
|
|
if (typeof password !== 'string' || password.length < minLen) {
|
|
throw new ApiError(ERROR_CODES.WEAK_PASSWORD, `Password must be at least ${minLen} characters`, 400);
|
|
}
|
|
const requireMixed = config.get<boolean>('PASSWORD_REQUIRE_MIXED', true);
|
|
if (requireMixed) {
|
|
const hasUpper = /[A-Z]/.test(password);
|
|
const hasLower = /[a-z]/.test(password);
|
|
const hasDigit = /[0-9]/.test(password);
|
|
const hasSymbol = /[^A-Za-z0-9]/.test(password);
|
|
if (!(hasUpper && hasLower && hasDigit && hasSymbol)) {
|
|
throw new ApiError(ERROR_CODES.WEAK_PASSWORD, 'Password must include upper, lower, digit, and symbol', 400);
|
|
}
|
|
}
|
|
} |