Does FusionAuth normalize Unicode characters in passwords before hashing?
-
I'm trying to understand how FusionAuth handles Unicode characters in user passwords.From testing, it appears that:
- Unicode characters are accepted as valid characters in passwords
- No Unicode normalization occurs before hashing the password
Can someone confirm whether FusionAuth performs any Unicode normalization (such as NFC, NFD, NFKC, or NFKD) on passwords before hashing them? Or does FusionAuth hash the raw bytes exactly as received?
This is important for understanding how passwords with visually identical but technically different Unicode representations (e.g., composed vs. decomposed characters) would be handled.
-
FusionAuth does not perform Unicode normalization on passwords before hashing.
Passwords are hashed using the raw bytes exactly as received from the client. This means:
- If a user sets a password with Unicode characters, those exact byte sequences are hashed
- Different Unicode representations of visually identical characters (e.g., é as a single composed character U+00E9 vs. e + combining acute accent U+0065 U+0301) will result in different password hashes
- No normalization forms (NFC, NFD, NFKC, NFKD) are applied
This behavior means you should ensure consistent encoding at the application level if Unicode normalization is important for your use case. The password validation will only succeed if the exact same byte sequence is provided during authentication.
Additional Context
FusionAuth fully supports Unicode characters in passwords, which is recommended for both usability and security reasons. When FusionAuth validates passwords for special characters, it processes them as Unicode strings (using Java's
Character.isAlphabetic()andCharacter.isDigit()methods on 16-bit Unicode values), confirming that passwords are handled as Unicode throughout the system.There are no inherent limitations on which Unicode characters can be used in passwords stored in FusionAuth, though you can configure password validation rules to enforce specific requirements for your tenant.
Related Documentation
- Password-Hashing Algorithms - Overview of FusionAuth's password hashing schemes (PBKDF2, Bcrypt, etc.)
- Custom Password Hashing - Information on implementing custom password hashing schemes
- Password Validation Rules - API for retrieving and configuring password validation rules
- Client-side Password Rule Validation - Guide for implementing password validation in your client application
- Are there any disallowed characters in passwords? - Community discussion confirming no inherent character limitations
-
D dan has marked this topic as solved
-
D dan moved this topic from Staged