Bug 1389783 - "RHOSP:Configure Overcloud" screen allows entering passwords less than 8 characters
Summary: "RHOSP:Configure Overcloud" screen allows entering passwords less than 8 char...
Keywords:
Status: CLOSED NOTABUG
Alias: None
Product: Red Hat Quickstart Cloud Installer
Classification: Red Hat
Component: WebUI
Version: 1.1
Hardware: Unspecified
OS: Unspecified
unspecified
unspecified
Target Milestone: ---
: 1.1
Assignee: Derek Whatley
QA Contact: Sudhir Mallamprabhakara
URL:
Whiteboard:
Depends On:
Blocks:
TreeView+ depends on / blocked
 
Reported: 2016-10-28 15:18 UTC by James Olin Oden
Modified: 2016-11-22 15:16 UTC (History)
3 users (show)

Fixed In Version:
Doc Type: If docs needed, set a value
Doc Text:
Clone Of:
Environment:
Last Closed: 2016-11-22 15:16:51 UTC
Target Upstream Version:


Attachments (Terms of Use)

Description James Olin Oden 2016-10-28 15:18:15 UTC
Description of problem:
I was testing if I could enter a password of less than 8 characters, and I found as long as the passwords matched for "Admin Password" and "Confirm Password" you could enter a password as small as one character and then proceed to the next screen.

Version-Release number of selected component (if applicable):
QCI-1.1-RHEL-7-20161026.t.0

How reproducible:
always

Steps to Reproduce:
1.  Do a deployment with OSP.
2.  When you get to the "RHOSP:Configure Overcloud" screen, try to enter a
    password of less than 8 characters.

Actual results:
The next button becomes ungrayed and you can proceed to the next screen.

Expected results:
An error should be printed saying that passwords must be 8 or more characters, and the next button should not be clickable.

Comment 2 John Matthews 2016-10-31 19:10:06 UTC
Let's investigate what the limitation is from OSP perspective and update WebUI/Backend validation to do the same.

Comment 3 Jason Montleon 2016-11-18 20:25:22 UTC
OSP is not enforcing anything. I logged into horizon and changed my password to 'a'. It was happy to let me do so.

Comment 5 Derek Whatley 2016-11-22 15:16:51 UTC
Changed password from OSP 10 WebUI, found that there is no limitation from the on password length. Also tested OSP deploy with a 1 char password and found that deploy completed successfully.


Note You need to log in before you can comment on or make changes to this bug.