you are viewing a single comment's thread
view the rest of the comments
[–] 112 points 3 weeks ago (37 children)

Auto fill likes to put a space after the name that often will make these forms freak out.

  • source
  • hideshow 37 child comments
  • [–] 63 points 3 weeks ago (7 children)

    Not always. My mortgage company uses a software where it treats the password as invalid if it’s autofilled. I have to copy and paste the password into the box to remove the error.

    Why people and companies need to make things purposefully difficult is beyond me. This shit is decades old and solved. Yet, they’re still constantly broken.

  • source
  • parent
  • hideshow 7 child comments
  • [–] 23 points 3 weeks ago (2 children)

    My old bank would not allow pasted passwords, nor autofill. For a while PayPal was the same way.

  • source
  • parent
  • hideshow 2 child comments
  • [–] 4 points 3 weeks ago (1 child)

    From my experience, I think this also happens because of badly written code, where it tries to detect user input to do validation, but it handles events incorrectly and sees autofill as invalid.

  • source
  • parent
  • hideshow 1 child comment
  • [–] 2 points 3 weeks ago

    I found that a lot of banks reject it unless both of the fields have been active inputs.

    So do the auto fill, then click each field so it thinks they were both used, then click login.

    Dumb, but two of my financial institutions require it.

  • source
  • parent
  • [–] 15 points 3 weeks ago (14 children)

    Spaces are valid within names.

  • source
  • parent
  • hideshow 14 child comments
  • [–] 8 points 3 weeks ago (13 children)

    Are they valid after names? I mean I suppose they could be, but how could you ever, and I mean ever, write out the name in that case?

  • source
  • parent
  • hideshow 13 child comments
  • [–] 25 points 3 weeks ago (8 children)

    No but the software should just remove excess whitespace instead of complaining

  • source
  • parent
  • hideshow 8 child comments
  • [–] 11 points 3 weeks ago (2 children)
  • [–] 1 point 3 weeks ago* (1 child)

    11 i thought all alphabets have been encoded in Unicode?
    15 Murica and Brazil have no rules whatsoever so i guess it can happen.

  • source
  • parent
  • hideshow 1 child comment
  • [–] 9 points 3 weeks ago (3 children)

    No it shouldn't. Text field entry should have two properties: (1) accept any UTF-8 string, (2) do not modify that string.

    If you want to make sure people don't make mistakes, take all your current validation code and turn it into a huge red warning that pops up if you try to continue with an "incorrect" field, asking you to double-check before proceeding. In the OP case it would be "You have entered an uncommon name", in case of extra whitespace it would be "There is whitespace after the name". Let the person themselves edit the field, don't change the text automatically at all.

    If those fields are used for anything other than interacting with the person entering them, validate during submission. In this case, charge a $1 HOLD on the credit card using the info provided.

    Anything other than that will lead to someone somewhere having an issue like the OP.

  • source
  • parent
  • hideshow 3 child comments
  • [–] 5 points 3 weeks ago (2 children)

    No, you should definitely sanitize the names if you are going to display them anywhere. You don't need JS to execute just because it's in someone's name, and that would also cause it to display incorrectly as the JS portion would not be shown. Getting rid of excess whitespace is fine aswell as it does not change the name

  • source
  • parent
  • hideshow 2 child comments
  • [–] 11 points 3 weeks ago* (last edited 3 weeks ago) (1 child)

    That's just awful security practices. You must not replace proper code/data separation with user input sanitization. If you are just pulling names from a database and inserting them into your DOM directly you're doing things majorly wrong and half your codebase probably needs rewriting from scratch.

    If your stack does not support code/data separation, you should escape at the point of use/point of interface with other software, not at the point of user data entry.

    You should not "sanitize" something as personal as a name. It is up to the individual to identify themselves as they see fit, whether it is some weird legal name or just how they want to present. For every "rule" about names you can think of, there will be an exception somewhere.

    In fact, even splitting up the name field into "first name" and "last name" is already wrong. It should just be "name". If you need there to be a separate "first name" and "last name" for some reason (e.g. an external system which requires it), allow leaving either one as empty. Bonus points if you have independent "legal name" and "how would you like to be called" fields.

    Getting rid of excess whitespace is fine aswell as it does not change the name

    As a responsible developer you must not assume this. Especially if your software interacts with other systems. You never know what dumb shit some other system has got up to, maybe a clerk somewhere accidentally entered someone's name with a space and that person desperately needs to use your software while they're getting things fixed.

    As an immigrant, I have been personally strongly inconvenienced by user input validation very often. For example, a tax agency system (which has my passport number recorded with a space) rejected automatic declarations from my bank (where the system did not allow spaces in the passport number) so I had to fill my tax declarations manually for a while. Or my bank rejecting bills from the water utility because the utility's system required entering two surnames, and I only have one, so they just put it in there twice. The amount of services which reject my pretty normal-looking self-hosted email address with "enter a valid email address" (presumably it must end in @gmail.com or @outlook.com) is staggering. This kind of bullshit is widespread and it needs to stop. You as a developer don't know better than the person entering the data about themselves.

  • source
  • parent
  • hideshow 1 child comment
  • [–] 5 points 3 weeks ago

    100% this.

    So many places do these things wrong and just make wild assumptions based on their limited PoV.

    I just spent a month adding international phone, name, and postal code support to a legacy app at my job.

    They weren’t even consistent with their enforcement inside of the app.

    Don’t add validation for anything unless you understand 100% of the cases. You should use premade libraries or tools in most cases because you will do it incorrectly.

    The rules around passwords are equally as dumb

  • source
  • parent
  • [–] 8 points 3 weeks ago (3 children)

    Who are you to judge that my name isn't valid? I can be " Bart 2" if I want to be.

  • source
  • parent
  • hideshow 3 child comments
  • [–] 6 points 3 weeks ago (11 children)

    Couldn't you just make it so the text box doesn't accept spaces to prevent that? Why allow a character to be input that makes the field invalid?

  • source
  • parent
  • hideshow 11 child comments
  • [–] 27 points 3 weeks ago*

    Yeah, that's also a bad idea, there's plenty of (mostly none-western) forenames that contain spaces, and plenty of surnames that contain spaces all over the world (Charles de Gaul, Guy Manuel de Hommen-baron)

    All they really need to do is to onSubmit do a .trim() to the name

  • source
  • parent
  • [–] 16 points 3 weeks ago (2 children)

    Because even if a space at the end of the name should be considered invalid, people can have names with spaces inside.

  • source
  • parent
  • hideshow 2 child comments
  • [–] 8 points 3 weeks ago (1 child)

    This is true. I know someone with a legal first name that's two words. He's a kid I work with. His parents made a point that his name isn't one or the other, it's both, and we are to address him as such.

    To my understanding (as a non-tech person who consumes tech-related media), name fields are commonly culturally biased. Usually it impacts last names, which can vary in size and layout across the world, sometimes including hyphens (which some systems don't like either.) Super short or long names also run into problems. Not everyone has one first name, one middle name, and one last name, but a lot of systems aren't designed to handle that kind of variation.

  • source
  • parent
  • hideshow 1 child comment
  • [–] 8 points 3 weeks ago (2 children)

    Nah, backend is hard, and they only know JS.

  • source
  • parent
  • hideshow 2 child comments
  • [–] 7 points 3 weeks ago (1 child)

    As a primarily backend engineer, I think the opposite here. The backend makes sense, JS is just a nightmare.

  • source
  • parent
  • hideshow 1 child comment
  • [–] 4 points 3 weeks ago* (last edited 3 weeks ago)

    From the typical web developer' view of course. They don't even know the <form><input type="submit"> thing anymore nowadays, neither the people who developed their framework. Can't apply for a job, because the js-form has a bug!

  • source
  • parent
  • [–] 7 points 3 weeks ago* (3 children)

    Of course you can. But whoever developed the form didn't care about their craft.

  • source
  • parent
  • hideshow 3 child comments
  • [–] 5 points 3 weeks ago*

    Japan has gotten a lot better but you still run into shit for this sometimes. First and middle names often have to be input without a space, so you end up with Johnwendell Anderson. And sometimes forms require names to be input with the Japanese phonetic alphabet (which lacks a lot of letters in English), and then if it doesn't match some document you need to verify an online input there can be trouble. So Jeeves would become Jiibuzu, and good luck matching that to your passport at the airport.

  • source
  • parent