<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:dc="http://purl.org/dc/elements/1.1/">
  <channel>
    <title>DEV Community: FUG</title>
    <description>The latest articles on DEV Community by FUG (@neulketing).</description>
    <link>https://dev.to/neulketing</link>
    <image>
      <url>https://media2.dev.to/dynamic/image/width=90,height=90,fit=cover,gravity=auto,format=auto/https:%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Fuser%2Fprofile_image%2F4169781%2F972e6bb8-2aad-4cb2-a0d0-19625a6d055e.png</url>
      <title>DEV Community: FUG</title>
      <link>https://dev.to/neulketing</link>
    </image>
    <atom:link rel="self" type="application/rss+xml" href="https://dev.to/feed/neulketing"/>
    <language>en</language>
    <item>
      <title>QR Error Correction, Center Logos, and the Difference Between Static and Redirect Codes</title>
      <dc:creator>FUG</dc:creator>
      <pubDate>Thu, 08 Oct 2026 20:57:50 +0000</pubDate>
      <link>https://dev.to/neulketing/qr-error-correction-center-logos-and-the-difference-between-static-and-redirect-codes-196a</link>
      <guid>https://dev.to/neulketing/qr-error-correction-center-logos-and-the-difference-between-static-and-redirect-codes-196a</guid>
      <description>&lt;p&gt;As of October 8, 2026&lt;/p&gt;

&lt;h2&gt;
  
  
  What a QR code can recover
&lt;/h2&gt;

&lt;p&gt;When we add a logo to a QR code, we are deliberately covering part of the symbol. That sounds like an error, because it is one. The reason a phone can sometimes read the result is that QR codes encode redundant information using Reed–Solomon error correction. We build free web tools, and this is one of the places where understanding a small technical detail makes a large practical difference.&lt;/p&gt;

&lt;p&gt;QR codes offer four commonly named error correction levels: L, M, Q, and H. Higher correction adds redundancy, but it also takes capacity. Given the same content, a higher level may require a denser symbol. The percentages typically associated with each level describe approximate recoverable damage to codewords, &lt;strong&gt;not&lt;/strong&gt; a guarantee that a logo covering that percentage of the visible square is safe.&lt;/p&gt;

&lt;div class="table-wrapper-paragraph"&gt;&lt;table&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th&gt;Level&lt;/th&gt;
&lt;th&gt;Approximate recovery&lt;/th&gt;
&lt;th&gt;Typical decision&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;L&lt;/td&gt;
&lt;td&gt;7%&lt;/td&gt;
&lt;td&gt;Clean, unobstructed environments&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;M&lt;/td&gt;
&lt;td&gt;15%&lt;/td&gt;
&lt;td&gt;General-purpose codes&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Q&lt;/td&gt;
&lt;td&gt;25%&lt;/td&gt;
&lt;td&gt;Modest decoration with testing&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;H&lt;/td&gt;
&lt;td&gt;30%&lt;/td&gt;
&lt;td&gt;More margin for a centered logo&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;&lt;/div&gt;

&lt;p&gt;A central logo is particularly unforgiving when it overlaps functional patterns or when the code is already dense. The three large position markers, their surrounding quiet regions, and other structural elements are essential. Error correction cannot repair every arbitrary shape of damage.&lt;/p&gt;

&lt;h2&gt;
  
  
  A minimal implementation
&lt;/h2&gt;

&lt;p&gt;The familiar open-source JavaScript &lt;code&gt;qrcode&lt;/code&gt; package allows a level to be selected explicitly. For a simple test page, an example looks like this:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight javascript"&gt;&lt;code&gt;&lt;span class="k"&gt;import&lt;/span&gt; &lt;span class="nx"&gt;QRCode&lt;/span&gt; &lt;span class="k"&gt;from&lt;/span&gt; &lt;span class="dl"&gt;"&lt;/span&gt;&lt;span class="s2"&gt;qrcode&lt;/span&gt;&lt;span class="dl"&gt;"&lt;/span&gt;&lt;span class="p"&gt;;&lt;/span&gt;

&lt;span class="kd"&gt;const&lt;/span&gt; &lt;span class="nx"&gt;destination&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="dl"&gt;"&lt;/span&gt;&lt;span class="s2"&gt;https://example.org/info&lt;/span&gt;&lt;span class="dl"&gt;"&lt;/span&gt;&lt;span class="p"&gt;;&lt;/span&gt;
&lt;span class="kd"&gt;const&lt;/span&gt; &lt;span class="nx"&gt;pngDataUrl&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="k"&gt;await&lt;/span&gt; &lt;span class="nx"&gt;QRCode&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nf"&gt;toDataURL&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="nx"&gt;destination&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="p"&gt;{&lt;/span&gt;
  &lt;span class="na"&gt;errorCorrectionLevel&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt; &lt;span class="dl"&gt;"&lt;/span&gt;&lt;span class="s2"&gt;H&lt;/span&gt;&lt;span class="dl"&gt;"&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;
  &lt;span class="na"&gt;margin&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt; &lt;span class="mi"&gt;4&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;
  &lt;span class="na"&gt;width&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt; &lt;span class="mi"&gt;640&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;
&lt;span class="p"&gt;});&lt;/span&gt;

&lt;span class="nb"&gt;document&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nf"&gt;querySelector&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="dl"&gt;"&lt;/span&gt;&lt;span class="s2"&gt;#preview&lt;/span&gt;&lt;span class="dl"&gt;"&lt;/span&gt;&lt;span class="p"&gt;).&lt;/span&gt;&lt;span class="nx"&gt;src&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="nx"&gt;pngDataUrl&lt;/span&gt;&lt;span class="p"&gt;;&lt;/span&gt;
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;This example generates a normal QR image. It does &lt;strong&gt;not&lt;/strong&gt; add a logo or prove that one is safe. If your UI overlays a logo afterward, you need a separate scan test of the finished composite. Keep the destination short when possible, because longer payloads can produce more modules. Test with multiple phones, camera distances, and lighting conditions, including the worst case you expect on paper.&lt;/p&gt;

&lt;p&gt;The margin option matters too. A QR code needs a quiet zone, usually at least four modules of uninterrupted background around the symbol. Cropping tightly for visual balance can break recognition even when the central data remains untouched.&lt;/p&gt;

&lt;h2&gt;
  
  
  Static payloads versus redirect services
&lt;/h2&gt;

&lt;p&gt;A static QR code contains the destination itself, such as a URL, Wi-Fi configuration, or contact fields. A redirect-based dynamic service commonly puts its own short URL in the symbol and forwards scans to the destination configured on its server. That approach can make the destination editable, but it also adds a service dependency.&lt;/p&gt;

&lt;p&gt;People often say a static QR code never expires. More precisely, the &lt;strong&gt;encoded data&lt;/strong&gt; does not carry a service-imposed expiration date. The destination website can still shut down, a domain can lapse, a Wi-Fi password can change, or an event can end. The pattern on the page stays the same, but what it points to may stop working.&lt;/p&gt;

&lt;p&gt;For a long-lived poster, we prefer an address the publisher controls. We also suggest printing the human-readable URL nearby. A scan failure should not make the information inaccessible.&lt;/p&gt;

&lt;h2&gt;
  
  
  PNG or SVG for production?
&lt;/h2&gt;

&lt;p&gt;PNG is a raster image. Its quality depends on the exported pixel dimensions relative to the size at which it is printed. A sufficiently large PNG can work perfectly well on a small card, but enlarging a small export introduces blurry edges. SVG uses vectors, so a designer can scale it to a larger sign without interpolation blur.&lt;/p&gt;

&lt;p&gt;Neither format rescues poor contrast, an undersized quiet zone, or an excessively ornate mark. Dark modules on a light background remain the safest starting point. Color combinations should be inspected in grayscale as well as on screen. A glossy surface or reflected light can undermine an apparently strong design.&lt;/p&gt;

&lt;p&gt;When handing files to a print shop, communicate the final physical dimensions. Exporting a huge bitmap without knowing the target size is less useful than confirming the final module size and printing a proof.&lt;/p&gt;

&lt;h2&gt;
  
  
  Our review routine before putting a QR code in public
&lt;/h2&gt;

&lt;p&gt;We first generate an undecorated version and scan it. Then we raise the error correction level if a logo is necessary, keep the logo compact, and scan the resulting composition. We check the printed proof rather than trusting a monitor preview. Finally, we verify the exact payload, including capitalization and punctuation in the destination URL.&lt;/p&gt;

&lt;p&gt;We treat QR codes as interfaces, not decoration. Their job is to transfer a small piece of information reliably. A beautiful code that nobody can scan fails that job.&lt;/p&gt;

&lt;h2&gt;
  
  
  FAQ
&lt;/h2&gt;

&lt;h3&gt;
  
  
  Does level H guarantee that a large logo will scan?
&lt;/h3&gt;

&lt;p&gt;No. H adds more recovery capacity, but location, density, contrast, printing, and decoder behavior still matter. The finished code must be tested.&lt;/p&gt;

&lt;h3&gt;
  
  
  Does a static QR code need an account or monthly renewal?
&lt;/h3&gt;

&lt;p&gt;The encoded pattern needs neither. Whether the resource at the destination remains available is a separate question.&lt;/p&gt;

&lt;h3&gt;
  
  
  Which download should we use for a poster?
&lt;/h3&gt;

&lt;p&gt;SVG is convenient for scaling in a print layout. A large, sharply rendered PNG may also work when the final dimensions are known.&lt;/p&gt;

&lt;p&gt;We made a free browser-based QR generator with nine payload types, options for logos, colors, and shapes, and PNG or SVG downloads. Codes are generated in the browser without a redirect layer; it also includes a separate group check-in room feature. Try the &lt;a href="https://makeqr.fyi/en/" rel="noopener noreferrer"&gt;free QR generator&lt;/a&gt;.&lt;/p&gt;

</description>
      <category>qrcode</category>
      <category>javascript</category>
      <category>printing</category>
      <category>webdev</category>
    </item>
    <item>
      <title>Check a Password Against a Breach List Without Sending the Password</title>
      <dc:creator>FUG</dc:creator>
      <pubDate>Wed, 07 Oct 2026 20:11:23 +0000</pubDate>
      <link>https://dev.to/neulketing/check-a-password-against-a-breach-list-without-sending-the-password-4edf</link>
      <guid>https://dev.to/neulketing/check-a-password-against-a-breach-list-without-sending-the-password-4edf</guid>
      <description>&lt;p&gt;As of October 8, 2026&lt;/p&gt;

&lt;p&gt;A password check can query a breach list without putting the password in an HTTP request. The browser hashes the input, sends five hexadecimal characters, and checks the returned candidates locally. We build small web tools, and we like this approach because the network boundary is explicit enough to inspect.&lt;/p&gt;

&lt;p&gt;Have I Been Pwned provides this pattern through its Pwned Passwords range endpoint. The useful question for developers is what crosses that boundary, what stays in memory, and what the answer actually establishes.&lt;/p&gt;

&lt;h2&gt;
  
  
  Follow the value through the browser
&lt;/h2&gt;

&lt;p&gt;SHA-1 produces a 160-bit digest, represented here as 40 hexadecimal characters. Split that string into a five-character prefix and a 35-character suffix. Request &lt;code&gt;https://api.pwnedpasswords.com/range/{prefix}&lt;/code&gt;, substituting the prefix. The response contains candidate suffixes and their occurrence counts.&lt;/p&gt;

&lt;p&gt;The browser compares its own suffix with those candidates. It never needs to transmit the remaining hash characters to finish the lookup.&lt;/p&gt;

&lt;div class="table-wrapper-paragraph"&gt;&lt;table&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th&gt;Value&lt;/th&gt;
&lt;th&gt;Where it is used&lt;/th&gt;
&lt;th&gt;Sent in the range request?&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;Original password&lt;/td&gt;
&lt;td&gt;Browser input and hashing&lt;/td&gt;
&lt;td&gt;No&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Complete SHA-1 hash&lt;/td&gt;
&lt;td&gt;Browser memory&lt;/td&gt;
&lt;td&gt;No&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;First five hexadecimal characters&lt;/td&gt;
&lt;td&gt;Range URL&lt;/td&gt;
&lt;td&gt;Yes&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Remaining 35 characters&lt;/td&gt;
&lt;td&gt;Local comparison&lt;/td&gt;
&lt;td&gt;No&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Candidate suffixes and counts&lt;/td&gt;
&lt;td&gt;Response parsing&lt;/td&gt;
&lt;td&gt;Returned by the service&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;&lt;/div&gt;

&lt;p&gt;This is the k-anonymity lookup pattern: one prefix identifies a group of candidate hashes rather than identifying the complete hash in the request. It reduces disclosure. It does not make the request anonymous or hide ordinary network metadata from the service.&lt;/p&gt;

&lt;h2&gt;
  
  
  A browser function you can run
&lt;/h2&gt;

&lt;p&gt;Use this on an HTTPS page or localhost, where the browser's Web Crypto API is available. Call it from a submit handler with the password field's value. For experiments, use a disposable test string rather than a real credential.&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight javascript"&gt;&lt;code&gt;&lt;span class="k"&gt;async&lt;/span&gt; &lt;span class="kd"&gt;function&lt;/span&gt; &lt;span class="nf"&gt;breachCount&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="nx"&gt;password&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt; &lt;span class="p"&gt;{&lt;/span&gt;
  &lt;span class="kd"&gt;const&lt;/span&gt; &lt;span class="nx"&gt;bytes&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="k"&gt;new&lt;/span&gt; &lt;span class="nc"&gt;TextEncoder&lt;/span&gt;&lt;span class="p"&gt;().&lt;/span&gt;&lt;span class="nf"&gt;encode&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="nx"&gt;password&lt;/span&gt;&lt;span class="p"&gt;);&lt;/span&gt;
  &lt;span class="kd"&gt;const&lt;/span&gt; &lt;span class="nx"&gt;digest&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="k"&gt;await&lt;/span&gt; &lt;span class="nx"&gt;crypto&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nx"&gt;subtle&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nf"&gt;digest&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="dl"&gt;'&lt;/span&gt;&lt;span class="s1"&gt;SHA-1&lt;/span&gt;&lt;span class="dl"&gt;'&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="nx"&gt;bytes&lt;/span&gt;&lt;span class="p"&gt;);&lt;/span&gt;
  &lt;span class="kd"&gt;const&lt;/span&gt; &lt;span class="nx"&gt;hash&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="nb"&gt;Array&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="k"&gt;from&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="k"&gt;new&lt;/span&gt; &lt;span class="nc"&gt;Uint8Array&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="nx"&gt;digest&lt;/span&gt;&lt;span class="p"&gt;),&lt;/span&gt; &lt;span class="nx"&gt;byte&lt;/span&gt; &lt;span class="o"&gt;=&amp;gt;&lt;/span&gt;
    &lt;span class="nx"&gt;byte&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nf"&gt;toString&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="mi"&gt;16&lt;/span&gt;&lt;span class="p"&gt;).&lt;/span&gt;&lt;span class="nf"&gt;padStart&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="mi"&gt;2&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="dl"&gt;'&lt;/span&gt;&lt;span class="s1"&gt;0&lt;/span&gt;&lt;span class="dl"&gt;'&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;
  &lt;span class="p"&gt;).&lt;/span&gt;&lt;span class="nf"&gt;join&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="dl"&gt;''&lt;/span&gt;&lt;span class="p"&gt;).&lt;/span&gt;&lt;span class="nf"&gt;toUpperCase&lt;/span&gt;&lt;span class="p"&gt;();&lt;/span&gt;

  &lt;span class="kd"&gt;const&lt;/span&gt; &lt;span class="nx"&gt;prefix&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="nx"&gt;hash&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nf"&gt;slice&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="mi"&gt;0&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="mi"&gt;5&lt;/span&gt;&lt;span class="p"&gt;);&lt;/span&gt;
  &lt;span class="kd"&gt;const&lt;/span&gt; &lt;span class="nx"&gt;suffix&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="nx"&gt;hash&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nf"&gt;slice&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="mi"&gt;5&lt;/span&gt;&lt;span class="p"&gt;);&lt;/span&gt;
  &lt;span class="kd"&gt;const&lt;/span&gt; &lt;span class="nx"&gt;response&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="k"&gt;await&lt;/span&gt; &lt;span class="nf"&gt;fetch&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;
    &lt;span class="s2"&gt;`https://api.pwnedpasswords.com/range/&lt;/span&gt;&lt;span class="p"&gt;${&lt;/span&gt;&lt;span class="nx"&gt;prefix&lt;/span&gt;&lt;span class="p"&gt;}&lt;/span&gt;&lt;span class="s2"&gt;`&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;
    &lt;span class="p"&gt;{&lt;/span&gt; &lt;span class="na"&gt;headers&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt; &lt;span class="p"&gt;{&lt;/span&gt; &lt;span class="dl"&gt;'&lt;/span&gt;&lt;span class="s1"&gt;Add-Padding&lt;/span&gt;&lt;span class="dl"&gt;'&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt; &lt;span class="dl"&gt;'&lt;/span&gt;&lt;span class="s1"&gt;true&lt;/span&gt;&lt;span class="dl"&gt;'&lt;/span&gt; &lt;span class="p"&gt;}&lt;/span&gt; &lt;span class="p"&gt;}&lt;/span&gt;
  &lt;span class="p"&gt;);&lt;/span&gt;
  &lt;span class="k"&gt;if &lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="o"&gt;!&lt;/span&gt;&lt;span class="nx"&gt;response&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nx"&gt;ok&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt; &lt;span class="p"&gt;{&lt;/span&gt;
    &lt;span class="k"&gt;throw&lt;/span&gt; &lt;span class="k"&gt;new&lt;/span&gt; &lt;span class="nc"&gt;Error&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="s2"&gt;`Lookup failed: HTTP &lt;/span&gt;&lt;span class="p"&gt;${&lt;/span&gt;&lt;span class="nx"&gt;response&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nx"&gt;status&lt;/span&gt;&lt;span class="p"&gt;}&lt;/span&gt;&lt;span class="s2"&gt;`&lt;/span&gt;&lt;span class="p"&gt;);&lt;/span&gt;
  &lt;span class="p"&gt;}&lt;/span&gt;

  &lt;span class="kd"&gt;const&lt;/span&gt; &lt;span class="nx"&gt;lines&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="k"&gt;await&lt;/span&gt; &lt;span class="nx"&gt;response&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nf"&gt;text&lt;/span&gt;&lt;span class="p"&gt;()).&lt;/span&gt;&lt;span class="nf"&gt;trim&lt;/span&gt;&lt;span class="p"&gt;().&lt;/span&gt;&lt;span class="nf"&gt;split&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="sr"&gt;/&lt;/span&gt;&lt;span class="se"&gt;\r?\n&lt;/span&gt;&lt;span class="sr"&gt;/&lt;/span&gt;&lt;span class="p"&gt;);&lt;/span&gt;
  &lt;span class="k"&gt;for &lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="kd"&gt;const&lt;/span&gt; &lt;span class="nx"&gt;line&lt;/span&gt; &lt;span class="k"&gt;of&lt;/span&gt; &lt;span class="nx"&gt;lines&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt; &lt;span class="p"&gt;{&lt;/span&gt;
    &lt;span class="kd"&gt;const&lt;/span&gt; &lt;span class="p"&gt;[&lt;/span&gt;&lt;span class="nx"&gt;candidate&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="nx"&gt;count&lt;/span&gt;&lt;span class="p"&gt;]&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="nx"&gt;line&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nf"&gt;trim&lt;/span&gt;&lt;span class="p"&gt;().&lt;/span&gt;&lt;span class="nf"&gt;split&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="dl"&gt;'&lt;/span&gt;&lt;span class="s1"&gt;:&lt;/span&gt;&lt;span class="dl"&gt;'&lt;/span&gt;&lt;span class="p"&gt;);&lt;/span&gt;
    &lt;span class="k"&gt;if &lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="nx"&gt;candidate&lt;/span&gt; &lt;span class="o"&gt;===&lt;/span&gt; &lt;span class="nx"&gt;suffix&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt; &lt;span class="k"&gt;return&lt;/span&gt; &lt;span class="nc"&gt;Number&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="nx"&gt;count&lt;/span&gt;&lt;span class="p"&gt;);&lt;/span&gt;
  &lt;span class="p"&gt;}&lt;/span&gt;
  &lt;span class="k"&gt;return&lt;/span&gt; &lt;span class="mi"&gt;0&lt;/span&gt;&lt;span class="p"&gt;;&lt;/span&gt;
&lt;span class="p"&gt;}&lt;/span&gt;
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;The function resolves to an occurrence count, or zero if its suffix is absent from a successful response. Network failures reject the promise; unsuccessful HTTP responses throw. A calling interface should catch those errors and show “check unavailable.” Turning a failed request into zero would give an unsupported reassurance.&lt;/p&gt;

&lt;p&gt;The optional &lt;code&gt;Add-Padding: true&lt;/code&gt; request header asks for padding entries, reducing information exposed through response size. Padding entries have zero counts. Our exact suffix comparison therefore still produces zero for a matching padding entry. The endpoint and padding behavior are documented in the &lt;a href="https://haveibeenpwned.com/API/v3#SearchingPwnedPasswordsByRange" rel="noopener noreferrer"&gt;official API reference&lt;/a&gt;.&lt;/p&gt;

&lt;h2&gt;
  
  
  Keep the surrounding interface honest
&lt;/h2&gt;

&lt;p&gt;Preserve the entered string exactly. Trimming whitespace or changing capitalization before hashing checks a different password. The uppercase conversion in the snippet applies only to the hexadecimal representation of the digest, so it does not alter the password itself.&lt;/p&gt;

&lt;p&gt;We would trigger this check after an explicit action rather than sending a request for every keystroke. Repeated prefixes from partially typed input disclose more than a single completed check. Keep password values out of URLs, console output, analytics events, and error reports, too.&lt;/p&gt;

&lt;p&gt;Local hashing describes this lookup mechanism. It cannot guarantee that every other script running on the page behaves safely. A browser implementation still needs a trustworthy page and careful handling of the input. SHA-1 also appears here for compatibility with the lookup dataset; it is not a suitable recommendation for storing account passwords.&lt;/p&gt;

&lt;h2&gt;
  
  
  Read the result as one piece of evidence
&lt;/h2&gt;

&lt;p&gt;A positive count says the password appears in the dataset. It does not identify which of the reader's accounts was affected, and the count is not a count of breaches involving that particular reader.&lt;/p&gt;

&lt;p&gt;Zero means no match was returned for this check. A new but predictable password can still be weak. Password strength estimation is a separate task, and a time-to-crack estimate depends on assumptions about guessing methods and attack conditions. Neither a score nor an estimated duration is a guarantee.&lt;/p&gt;

&lt;p&gt;Our free checker follows the local SHA-1 and five-character-prefix flow. It shows the breach count alongside a 0–100 security score and a time-to-crack estimate, and includes a strong-password generator. We describe those outputs separately so the lookup result does not masquerade as a complete security assessment.&lt;/p&gt;

&lt;h2&gt;
  
  
  FAQ
&lt;/h2&gt;

&lt;h3&gt;
  
  
  Does the service receive my password or its full hash?
&lt;/h3&gt;

&lt;p&gt;In the range request shown above, it receives the first five hexadecimal characters only. The password, full hash, and suffix comparison remain in the browser. That statement concerns this code path, not every possible script on a page.&lt;/p&gt;

&lt;h3&gt;
  
  
  Is a password safe if the count is zero?
&lt;/h3&gt;

&lt;p&gt;No. Absence from the returned dataset does not establish strength or uniqueness. We would still avoid reuse and choose a long, unpredictable password for each account.&lt;/p&gt;

&lt;h3&gt;
  
  
  Why use SHA-1 when it is unsuitable for password storage?
&lt;/h3&gt;

&lt;p&gt;Here it creates a lookup identifier compatible with the dataset. Secure password storage has different requirements, including resistance to repeated guessing. Reusing this snippet as a password storage design would confuse those two jobs.&lt;/p&gt;

&lt;p&gt;&lt;a href="https://pwcheck.fyi/en/" rel="noopener noreferrer"&gt;Check a password with our free tool&lt;/a&gt;&lt;/p&gt;

</description>
      <category>javascript</category>
      <category>security</category>
      <category>privacy</category>
      <category>webdev</category>
    </item>
  </channel>
</rss>
