Bug 1389783

Summary: "RHOSP:Configure Overcloud" screen allows entering passwords less than 8 characters
Product: Red Hat Quickstart Cloud Installer Reporter: James Olin Oden <joden>
Component: WebUIAssignee: Derek Whatley <dwhatley>
Status: CLOSED NOTABUG QA Contact: Sudhir Mallamprabhakara <smallamp>
Severity: unspecified Docs Contact:
Priority: unspecified    
Version: 1.1CC: dwhatley, jmontleo, qci-bugzillas
Target Milestone: ---Keywords: Triaged
Target Release: 1.1   
Hardware: Unspecified   
OS: Unspecified   
Whiteboard:
Fixed In Version: Doc Type: If docs needed, set a value
Doc Text:
Story Points: ---
Clone Of: Environment:
Last Closed: 2016-11-22 15:16:51 UTC Type: Bug
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:

Description James Olin Oden 2016-10-28 15:18:15 UTC
Description of problem:
I was testing if I could enter a password of less than 8 characters, and I found as long as the passwords matched for "Admin Password" and "Confirm Password" you could enter a password as small as one character and then proceed to the next screen.

Version-Release number of selected component (if applicable):
QCI-1.1-RHEL-7-20161026.t.0

How reproducible:
always

Steps to Reproduce:
1.  Do a deployment with OSP.
2.  When you get to the "RHOSP:Configure Overcloud" screen, try to enter a
    password of less than 8 characters.

Actual results:
The next button becomes ungrayed and you can proceed to the next screen.

Expected results:
An error should be printed saying that passwords must be 8 or more characters, and the next button should not be clickable.

Comment 2 John Matthews 2016-10-31 19:10:06 UTC
Let's investigate what the limitation is from OSP perspective and update WebUI/Backend validation to do the same.

Comment 3 Jason Montleon 2016-11-18 20:25:22 UTC
OSP is not enforcing anything. I logged into horizon and changed my password to 'a'. It was happy to let me do so.

Comment 5 Derek Whatley 2016-11-22 15:16:51 UTC
Changed password from OSP 10 WebUI, found that there is no limitation from the on password length. Also tested OSP deploy with a 1 char password and found that deploy completed successfully.