package com.codebyte.api.common.validation;

import jakarta.validation.ConstraintValidator;
import jakarta.validation.ConstraintValidatorContext;
import java.util.Locale;
import java.util.Set;

/**
 * Enforces the password policy: at least 12 characters and not on a small deny list of the most
 * common passwords. The deny list is intentionally short and illustrative; a production deployment
 * would back this with a breached-password service.
 */
public class StrongPasswordValidator implements ConstraintValidator<StrongPassword, String> {

    private static final int MIN_LENGTH = 12;

    private static final Set<String> COMMON_PASSWORDS =
            Set.of(
                    "password",
                    "passw0rd",
                    "password123",
                    "123456789012",
                    "qwertyuiop12",
                    "letmein12345",
                    "administrator",
                    "welcome12345",
                    "iloveyou1234",
                    "changeme1234");

    @Override
    public boolean isValid(String value, ConstraintValidatorContext context) {
        if (value == null || value.length() < MIN_LENGTH) {
            return false;
        }
        return !COMMON_PASSWORDS.contains(value.toLowerCase(Locale.ROOT));
    }
}
