Functional Weave
Code in Rust

auth.validate-password-change

Check a change-password form: current password given and correct, new one meeting the policy and different.

1.0.0 · published 2026-10-03 by charlie · Anterra

Pinned by 15 tests, run in TypeScript, Python and Rust.

What it does

Checks a change-password form in one call, after the API has asked `auth.password-hash` whether the current password is right, and answers in the shape an API's `validation_failed` error and a form both want:

matches = verifyPassword(currentPassword, user.passwordHash)
validatePasswordChange(currentPassword, newPassword, matches, user.email, user.name,
                       passwordPolicy("nist-800-63b-4-single-factor"))
# {valid: false, fields: {"currentPassword": "That is not your current password."}}

For example

  • validate_password_change(correct horse battery staple, a much longer passphrase here, true, ada@example.com, Ada Lovelace, name nist-800-63b-4-single-factor, min length 15, max length 128, min character c…) → valid true, fields … the right current password and a good new one
  • validate_password_change(correct horse battery stapel, a much longer passphrase here, false, ada@example.com, Ada Lovelace, name nist-800-63b-4-single-factor, min length 15, max length 128, min character …) → valid false, fields … the current password is wrong
  • validate_password_change(, a much longer passphrase here, false, ada@example.com, Ada Lovelace, name nist-800-63b-4-single-factor, min length 15, max length 128, min character classes 0, block common true…) → valid false, fields … the current password is empty

The function

The same function in TypeScript, Python and Rust, pinned by the same tests. Pick your language; the choice follows you around the registry.

pub fn validate_password_change(current_password: &str, new_password: &str, current_password_matches: bool, email: &str, name: &str, policy: &PasswordPolicy) -> PasswordChangeCheck
current_passwordstringas typed
new_passwordstringas typed; checked with auth.password-policy against the account's email and name
current_password_matchesboolwhat auth.password-hash's verifyPassword said about currentPassword and the stored hash
emailstringthe account's stored email, whose local part may not appear in the new password
namestringthe account's stored name, whose words may not appear in the new password
policyPasswordPolicyusually passwordPolicy("nist-800-63b-4-single-factor"), the one sign-up uses
returnsPasswordChangeCheckvalid, or a message for each field that needs fixing

The type it declares, generated into your project

/// A change-password form's verdict, shaped for an API's validation error and a form's field messages.
#[derive(Debug, Clone, PartialEq, Eq)]
pub struct PasswordChangeCheck {
    pub valid: bool,
    /// field name (currentPassword, newPassword) to message; empty when valid
    pub fields: Vec<(String, String)>,
}

Your code names it in one line, in the file that uses it

fune!(auth.validate-password-change@^1);  // then call validate_password_change(…)
impl/rust.rs · 64 lines · open · raw

Imports name this capability’s declared dependencies, which fune builds next to it in your project; each one links to its page.

use super::funejson::Value;  ← the fune runtime: the JSON value the test vectors use; fune build keeps it only where a signature takes one
use super::auth_password_policy_check_password::{check_password, password_policy_from_value};
use super::auth_password_policy_types::PasswordPolicy;

/// A change-password form checked in one call: the current password must be
/// given and correct, the new one must meet the policy and differ from it.
///
/// # Panics
/// Panics on a policy whose numbers make no sense.
pub fn validate_password_change(
    current_password: &str,
    new_password: &str,
    current_password_matches: bool,
    email: &str,
    name: &str,
    policy: &PasswordPolicy,
) -> PasswordChangeCheck {
    let mut fields: Vec<(String, String)> = Vec::new();

    if current_password.is_empty() {
        fields.push(("currentPassword".to_string(), "Enter your current password.".to_string()));
    } else if !current_password_matches {
        fields.push(("currentPassword".to_string(), "That is not your current password.".to_string()));
    }

    // Checked even when empty, so a nonsensical policy always panics.
    let check = check_password(new_password, Some(email), Some(name), policy);
    if new_password.is_empty() {
        fields.push(("newPassword".to_string(), "Enter a new password.".to_string()));
    } else {
        let mut messages: Vec<&str> = check.failures.iter().map(|f| f.message.as_str()).collect();
        if new_password == current_password {
            messages.push("Choose a password that is different from your current one.");
        }
        if !messages.is_empty() {
            fields.push(("newPassword".to_string(), messages.join(" ")));
        }
    }

    PasswordChangeCheck { valid: fields.is_empty(), fields }
}

pub fn password_change_check_to_value(check: &PasswordChangeCheck) -> Value {
    Value::obj(vec![
        ("valid", Value::Bool(check.valid)),
        (
            "fields",
            Value::Obj(check.fields.iter().map(|(k, v)| (k.clone(), Value::str(v))).collect()),
        ),
    ])
}

pub fn fune_vector(args: &[Value]) -> Value {
    // A non-string is an empty field, as in TypeScript and Python.
    let policy = password_policy_from_value(&args[5]);
    password_change_check_to_value(&validate_password_change(
        args[0].as_str(),
        args[1].as_str(),
        args[2].as_bool(),
        args[3].as_str(),
        args[4].as_str(),
        &policy,
    ))
}

Install

fune build

With that line in your source, in a Rust project (language rust in fune.project), fune build resolves it and its 1 dependency, pins them in fune.lock, downloads only the Rust package of each, and builds the code above into your project’s .fune/build, one readable file per capability with a header linking back here. A crate’s build.rs runs it before every compile. Or pin a range in fune.project and build in one step:

fune add auth.validate-password-change
Download for Rust auth.validate-password-change-1.0.0-rust.fune · 13,940 bytes sha256 bd7af22ea8b17c72d2f74cd1ffc59f6d2304afa53a9b9d865f8ccc07e15df5f8

The manifest, vectors and README with only the Rust implementation. Install it without the registry with fune add ./auth.validate-password-change-1.0.0-rust.fune, or fetch it from a terminal with fune pull auth.validate-password-change@1.0.0:rust.

The whole function, every language, is one file too: auth.validate-password-change-1.0.0.fune, 17,269 bytes, sha256 c95e8fac3c2b80b7c7368d312f2ba8b40486e94e4e24148e6e53940224cd20c1. It installs into a project of any language.

Customise it in your app

The seams this capability offers. Put a marker directly above a function of your own and fune build wires it into the built code; the package on the registry is not changed, the built file’s header lists it under CUSTOMISED, and fune hooks lists every hook in the project. How hooks work.

before — your function gets the arguments and returns them, changed or not, or throws to refuse the call.

// fune: before auth.validate-password-change

after — your function gets the result and the arguments, and returns the final result.

// fune: after auth.validate-password-change

replace — inside this capability’s code only, calls to a dependency go to your function, with the same signature. Other capabilities that use it are unaffected; write in * to replace it everywhere.

// fune: replace auth.password-policy in auth.validate-password-change

step — your function runs at a numbered point inside the function’s body, receives the in-scope values it names as parameters, and may return replacements. List the points with fune show auth.validate-password-change --steps.

// fune: step auth.validate-password-change after <n|label>

Tests

A version published now needs at least 8 tests for every function, and one that expects the error for each function that throws; the registry refuses it otherwise. fune verify --all runs each case in TypeScript, Python and Rust, and a project runs them again with fune verify. This page lists the cases; it does not run them. The exact JSON is vectors.json.

CaseArgumentsExpected
the right current password and a good new one correct horse battery staple, a much longer passphrase here, true, ada@example.com, Ada Lovelace, name nist-800-63b-4-single-factor, min length 15, max length 128, min character c… → valid true, fields …
the current password is wrong correct horse battery stapel, a much longer passphrase here, false, ada@example.com, Ada Lovelace, name nist-800-63b-4-single-factor, min length 15, max length 128, min character … → valid false, fields …
the current password is empty , a much longer passphrase here, false, ada@example.com, Ada Lovelace, name nist-800-63b-4-single-factor, min length 15, max length 128, min character classes 0, block common true… → valid false, fields …
an empty current password never counts as matching, whatever the flag says , a much longer passphrase here, true, ada@example.com, Ada Lovelace, name nist-800-63b-4-single-factor, min length 15, max length 128, min character classes 0, block common true,… → valid false, fields …
the new password is empty correct horse battery staple, , true, ada@example.com, Ada Lovelace, name nist-800-63b-4-single-factor, min length 15, max length 128, min character classes 0, block common true, … → valid false, fields …
both empty: current first, then new , , false, ada@example.com, Ada Lovelace, name nist-800-63b-4-single-factor, min length 15, max length 128, min character classes 0, block common true, block personal true → valid false, fields …
the new password is too short correct horse battery staple, short, true, ada@example.com, Ada Lovelace, name nist-800-63b-4-single-factor, min length 15, max length 128, min character classes 0, block common t… → valid false, fields …
the new password is short and common: every failure, joined correct horse battery staple, password, true, ada@example.com, Ada Lovelace, name nist-800-63b-4-single-factor, min length 15, max length 128, min character classes 0, block commo… → valid false, fields …
the new password contains the account's email local part and name correct horse battery staple, ada-lovelace-rules-ok, true, ada@example.com, Ada Lovelace, name nist-800-63b-4-single-factor, min length 15, max length 128, min character classes 0… → valid false, fields …
the new password is the current one correct horse battery staple, correct horse battery staple, true, ada@example.com, Ada Lovelace, name nist-800-63b-4-single-factor, min length 15, max length 128, min character cl… → valid false, fields …
Show the other 5 tests
CaseArgumentsExpected
the same and too short: the policy's failures come first shortpass, shortpass, true, ada@example.com, Ada Lovelace, name nist-800-63b-4-single-factor, min length 15, max length 128, min character classes 0, block common true, block pers… → valid false, fields …
a trailing space makes a different password: nothing is trimmed correct horse battery staple, correct horse battery staple , true, ada@example.com, Ada Lovelace, name nist-800-63b-4-single-factor, min length 15, max length 128, min character c… → valid true, fields …
a wrong current password and a bad new one: both fields nope, short, false, ada@example.com, Ada Lovelace, name nist-800-63b-4-single-factor, min length 15, max length 128, min character classes 0, block common true, block personal true → valid false, fields …
values that are not strings (a malformed JSON body) are treated as empty —, 12,345, false, ada@example.com, Ada Lovelace, name nist-800-63b-4-single-factor, min length 15, max length 128, min character classes 0, block common true, block personal true → valid false, fields …
a nonsensical policy is the caller's mistake correct horse battery staple, a much longer passphrase here, true, ada@example.com, Ada Lovelace, name nist-800-63b-4-single-factor, min length 0, max length 128, min character cl… → error: policy minLength must be a whole number of at least 1

More from the author

Checking the hash is not a pure function's job (it needs the stored hash), so its answer comes in as `currentPasswordMatches`; the rule of what to say about it lives here, next to the other messages. A wrong current password is a field message (400), not a 401: the person's session is fine, they mistyped.

**currentPassword**: empty is "Enter your current password."; otherwise `currentPasswordMatches` false is "That is not your current password.". An empty password never counts as matching, whatever the flag says.

**newPassword**: empty is "Enter a new password."; otherwise every failure of `auth.password-policy`'s `checkPassword` against the account's stored email and name, in the policy's order, and then "Choose a password that is different from your current one." when it is exactly the current password, all joined with a space. Use the same policy name sign-up uses, so a password that could not be chosen at sign-up cannot be chosen here either.

Passwords are compared exactly as typed: not trimmed and not case-folded, so `"correct horse battery staple "` with a trailing space is a different password. `fields` is keyed `currentPassword` then `newPassword`, the JSON body's own names. A value that is not a string is treated as empty. A nonsensical policy throws, as in `checkPassword`.

After a valid change the API stores a new hash and revokes every token the account holds (`auth.access-token`: bump the token version).

Files

PathBytes
README.md1,997
impl/python.py1,593
impl/rust.rs2,352
impl/typescript.ts1,566
vectors.json6,140