Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Highlights from the bug report[1][2]:

  - HTML spec allows it; says MAY, not MUST [3]
  - Affects only user pastes, not javascript edits
  - Affects all input boxes, not just password ones
  - New preference editor.truncate_user_pastes can restore old behavior
As a developer, I personally find the inconsistent behavior of maxLength unintuitive and am surprised a potentially-breaking change like this didn't have more discussion (although, the original bug report was open for 4 years). But as a user, I have some empathy for the team's desire to fix "broken" websites (e.g. where the login page has a shorter limit than the account creation page or backend).

[1] https://phabricator.services.mozilla.com/D71689

[2] https://bugzilla.mozilla.org/show_bug.cgi?id=1320229

[3] https://html.spec.whatwg.org/multipage/form-control-infrastr...



We discussed the problem on #security and we moved to bugzilla once we kinda had a solution (it is hard to discuss solutions on bugzilla. :) Here is a link to the chat: https://matrix.to/#/!xSFwJMLGSLXLaSUrHr:mozilla.org/$o3a38gf...


As someone whose user agent is Firefox, I’d rather that maxLength didn’t exist at all, and given that it does, my user agent ignoring that seems like the best solution to me.




Consider applying for YC's Fall 2026 batch! Applications are open till July 27.

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: