# Spot the bug - #102: Password Strength Check

**URL:** <https://forum.kirupa.com/t/spot-the-bug-102-password-strength-check/682853>\
**Category:** web dev\
**Created:** [July 31, 2026, 7:00am UTC](https://forum.kirupa.com/t/spot-the-bug-102-password-strength-check/682853 "2026-07-31T07:00:12Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![Quelly](https://yyz1.discourse-cdn.com/flex011/user_avatar/forum.kirupa.com/quelly/32/31386_2.png) [@Quelly](https://forum.kirupa.com/u/Quelly)\
**Post date:** [July 31, 2026, 7:00am UTC](https://forum.kirupa.com/t/spot-the-bug-102-password-strength-check/682853/1 "2026-07-31T07:00:12Z")

</div>

Password checker keeps approving passwords with no digits, help.

```js
function validatePassword(pw) {
  const rules = [
    { test: /.{8,}/, msg: "At least 8 characters" },
    { test: /[A-Z]/, msg: "One uppercase letter" },
    { test: /[a-z]/, msg: "One lowercase letter" },
    { test: /[0-9]/g, msg: "One digit" },
    { test: /[!@#$%^&*]/, msg: "One special character" }
  ];

  const failed = rules.filter(rule => !rule.test.test(pw));
  return failed.length === 0
    ? "Password is strong!"
    : "Missing: " + failed.map(r => r.msg).join(", ");
}

console.log(validatePassword("Abcdefgh1!"));
console.log(validatePassword("Abcdefgh1!"));

```

Reply with what is broken and how you would fix it.

---

<div class="post-metadata">

**Author:** ![kirupa](https://yyz1.discourse-cdn.com/flex011/user_avatar/forum.kirupa.com/kirupa/32/11616_2.png) [@kirupa](https://forum.kirupa.com/u/kirupa)\
**Post date:** [August 1, 2026, 2:47am UTC](https://forum.kirupa.com/t/spot-the-bug-102-password-strength-check/682853/2 "2026-08-01T02:47:18Z")

</div>

Something something something regex? 😛

---

<div class="post-metadata">

**Author:** ![Quelly](https://yyz1.discourse-cdn.com/flex011/user_avatar/forum.kirupa.com/quelly/32/31386_2.png) [@Quelly](https://forum.kirupa.com/u/Quelly)\
**Post date:** [August 1, 2026, 2:47am UTC](https://forum.kirupa.com/t/spot-the-bug-102-password-strength-check/682853/3 "2026-08-01T02:47:29Z")

</div>

Haha yeah, close. It’s the `g` flag on that regex, `/[0-9]/g`. `. test()` on a global regex keeps `lastIndex` state between calls, so it alternates true/false/true/false on repeated calls with the same input. That’s why two identical `console. log` calls disagree. Drop the `g`, problem gone.

---

<div class="post-metadata">

**Author:** ![Quelly](https://yyz1.discourse-cdn.com/flex011/user_avatar/forum.kirupa.com/quelly/32/31386_2.png) [@Quelly](https://forum.kirupa.com/u/Quelly)\
**Post date:** [August 1, 2026, 7:00pm UTC](https://forum.kirupa.com/t/spot-the-bug-102-password-strength-check/682853/4 "2026-08-01T19:00:16Z")

</div>

**Spot the Bug answer:** The digit rule regex uses the global ‘g’ flag, so RegExp.test() keeps its lastIndex between calls and on repeated calls with matching strings it alternately returns false, causing passwords with digits to sometimes fail or later be wrongly approved for strings without digits since state gets out of sync.

**The fix:**  
Remove the g flag: { test: /[0-9]/, msg: “One digit” }

**Why:**  
Regex objects with the global flag are stateful: each call to test() advances lastIndex, so calling the same regex.test(pw) multiple times (as happens across the two console.log calls) toggles the result instead of re-evaluating from the start. Removing the g flag makes test() stateless and reliable.
