[PM-43140] fix(browser): detect old password fields in change forms - #23030
Open
tmsteph wants to merge 1 commit into
Open
[PM-43140] fix(browser): detect old password fields in change forms#23030tmsteph wants to merge 1 commit into
tmsteph wants to merge 1 commit into
Conversation
Signed-off-by: Thomas Stephens <tmsteph1290@gmail.com>
Collaborator
|
Thank you for your contribution! We've added this to our internal tracking system for review. Details on our contribution process can be found here: https://contributing.bitwarden.com/contributing/pull-requests/community-pr-process. |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
🎟️ Tracking
Relates to #1620
📔 Objective
Password-change and password-expiry forms commonly use fields such as
oldPassword,currentPassword,newPassword, and a confirmation field.Bitwarden already has change-password notification logic for
password + newPassword, but the current-password classifier only recognized spaced phrases such ascurrent password. Compact field names likeoldPasswordorcurrentPasswordtherefore could fall through classification on multi-password forms and never be captured as the current password.Add conservative
current-password/old-passwordkeyword variants to the password-update classifier. Bitwarden's existing tokenizer removes hyphens, so these variants match compact field names (currentPassword,oldPassword) without broad fuzzy matching.The regression test covers an expired/change-password style form with
oldPassword,newPassword, and confirmation fields and verifies that the old-password field is classified asCurrentPasswordUpdate.Validation:
git diff --checkmainold-password->oldpassword, matchingoldPasswordI did not run the full browser test suite locally because the monorepo dependency install previously exhausted the available worker resources. CI can provide full project validation.
📸 Screenshots
Not applicable. This changes form-field classification only and reuses Bitwarden's existing change-password UI/notification flow.