security: limit the maximum password lenght to 72 characters to prevent possible...
security: limit the maximum password lenght to 72 characters to prevent possible
server side resource consumption attack.
- bcrypt heavy computation can lead to DOS using a very long password .eg 10**8 lenght.
- we allowed this on registration or on password update