dimanche 19 février 2017

Should retyped passwords be sent to the server too?

When registering for an account or when resetting a password of a web service, users are often required to type their password twice to ensure that they do not accidentally misspell their passwords.

If accidental misspelling is the only consideration for this feature, it would be acceptable (perhaps even better, from a website design perspective) for the retyped password to be validated by browser/client JavaScript rather than being sent to the server for validation.

Am I right that accidental misspelling is the only consideration for this feature?




Aucun commentaire:

Enregistrer un commentaire