Skip to content
Product block

New Password With Strength Meter

Set-a-new-password form with a four-step strength meter, confirm matching and errors announced rather than only coloured.

179 lineslucide-reactAdded 8 Aug 2026Updated 11 Sept 2026
  • reset password
  • strength meter
  • auth
  • validation

What's included

  • components/auth-reset-password.tsx
  • Needs lucide-react

Works with

  • React
  • Next.js
  • Tailwind CSS
  • TypeScript

npx hoverlab add auth-reset-password

Or over MCP, from your editor's agent — no account needed.

License

Free to read, copy and install, for personal and non-commercial projects. Shipping it in client work or a paid product needs Pro ($79 once). The source lands in your repo and stops being ours — no attribution, nothing to upgrade.

Was this useful?

Start a page with this section — add more, order them, and leave with the page source.

Preview

Choose a new password

It needs at least 8 characters. Longer beats complicated.

Rendered live in your current theme — this is the same component whose source is below, not a screenshot of it.

Source

components/auth-reset-password.tsx
'use client'

/**
 * <AuthResetPassword> — set a new password, with a strength meter.
 *
 * Strength is scored from character-class variety and length. That is a
 * rough heuristic and deliberately presented as one — the meter is advice,
 * and the only hard gate is the minimum length plus the confirm match.
 * Blocking submission on a strength score frustrates users with genuinely
 * strong passphrases that happen to be all lowercase.
 *
 * The confirmation mismatch is announced through `aria-live` and marked
 * with `aria-invalid`, so it is not conveyed by a red border alone.
 */

import * as React from 'react'
import { Eye, EyeOff, Loader2, KeyRound } from 'lucide-react'

export interface AuthResetPasswordProps {
  heading?: string
  minLength?: number
  onSubmit?: (password: string) => Promise<void>
  className?: string
}

const LEVELS = [
  { label: 'Too short', bar: 'bg-border', text: 'text-muted-foreground' },
  { label: 'Weak', bar: 'bg-red-500', text: 'text-red-500' },
  { label: 'Fair', bar: 'bg-amber-500', text: 'text-amber-500' },
  { label: 'Good', bar: 'bg-sky-500', text: 'text-sky-500' },
  { label: 'Strong', bar: 'bg-emerald-500', text: 'text-emerald-500' },
]

/** 0–4. Length gets the most weight; variety breaks the ties. */
function scorePassword(value: string, minLength: number): number {
  if (value.length < minLength) return 0

  let score = 1
  if (value.length >= minLength + 4) score += 1
  if (/[A-Z]/.test(value) && /[a-z]/.test(value)) score += 1
  if (/\d/.test(value) && /[^A-Za-z0-9]/.test(value)) score += 1

  return Math.min(4, score)
}

export function AuthResetPassword({
  heading = 'Choose a new password',
  minLength = 8,
  onSubmit,
  className = '',
}: AuthResetPasswordProps) {
  // Per-instance ids. A literal id in a reusable component is a
  // collision waiting for the second copy on the page — and a <label>
  // then resolves to whichever input rendered first.
  const uid = React.useId()
  const [password, setPassword] = React.useState('')
  const [confirm, setConfirm] = React.useState('')
  const [visible, setVisible] = React.useState(false)
  const [busy, setBusy] = React.useState(false)

  const score = scorePassword(password, minLength)
  const level = LEVELS[score]
  const longEnough = password.length >= minLength
  const mismatch = confirm.length > 0 && confirm !== password
  const canSubmit = longEnough && confirm === password && !busy

  async function handleSubmit(event: React.FormEvent) {
    event.preventDefault()
    if (!canSubmit) return
    setBusy(true)
    try {
      await onSubmit?.(password)
    } finally {
      setBusy(false)
    }
  }

  return (
    <div className={`flex min-h-96 w-full items-center justify-center p-6 ${className}`}>
      <div className="w-full max-w-sm rounded-2xl border border-border/60 bg-card/80 p-7 shadow-sm backdrop-blur">
        <div className="mb-5 inline-flex h-11 w-11 items-center justify-center rounded-xl bg-primary/15 text-primary">
          <KeyRound className="h-5 w-5" />
        </div>

        <h1 className="text-2xl font-bold tracking-tight">{heading}</h1>
        <p className="mt-1.5 text-sm text-muted-foreground">
          It needs at least {minLength} characters. Longer beats complicated.
        </p>

        <form onSubmit={handleSubmit} className="mt-6 space-y-4">
          <div>
            <label htmlFor={`${uid}-reset-password`} className="mb-1.5 block text-sm font-medium">
              New password
            </label>
            <div className="relative">
              <input
                id={`${uid}-reset-password`}
                type={visible ? 'text' : 'password'}
                required
                autoComplete="new-password"
                value={password}
                onChange={(e) => setPassword(e.target.value)}
                className="w-full rounded-xl border border-border/60 bg-background px-3.5 py-2.5 pe-11 text-sm outline-none transition-shadow focus-visible:ring-2 focus-visible:ring-primary"
              />
              <button
                type="button"
                onClick={() => setVisible((v) => !v)}
                aria-label={visible ? 'Hide password' : 'Show password'}
                aria-pressed={visible}
                className="absolute end-1.5 top-1/2 -translate-y-1/2 rounded-lg p-2 text-muted-foreground transition-colors hover:bg-muted hover:text-foreground"
              >
                {visible ? (
                  <EyeOff aria-hidden className="h-4 w-4" />
                ) : (
                  <Eye aria-hidden className="h-4 w-4" />
                )}
              </button>
            </div>

            {/* Strength meter */}
            <div className="mt-2.5 flex items-center gap-2">
              <div aria-hidden className="flex flex-1 gap-1">
                {[1, 2, 3, 4].map((step) => (
                  <span
                    key={step}
                    className={`h-1 flex-1 rounded-full transition-colors ${
                      score >= step ? level.bar : 'bg-border/60'
                    }`}
                  />
                ))}
              </div>
              <span className={`w-16 text-end text-xs font-medium ${level.text}`}>
                {password.length > 0 ? level.label : ''}
              </span>
            </div>
          </div>

          <div>
            <label htmlFor={`${uid}-reset-confirm`} className="mb-1.5 block text-sm font-medium">
              Confirm password
            </label>
            <input
              id={`${uid}-reset-confirm`}
              type={visible ? 'text' : 'password'}
              required
              autoComplete="new-password"
              aria-invalid={mismatch}
              aria-describedby={`${uid}-reset-confirm-error`}
              value={confirm}
              onChange={(e) => setConfirm(e.target.value)}
              className={`w-full rounded-xl border bg-background px-3.5 py-2.5 text-sm outline-none transition-shadow focus-visible:ring-2 ${
                mismatch
                  ? 'border-destructive focus-visible:ring-destructive'
                  : 'border-border/60 focus-visible:ring-primary'
              }`}
            />
            <p
              id={`${uid}-reset-confirm-error`}
              aria-live="polite"
              className="mt-1.5 min-h-4 text-xs text-destructive"
            >
              {mismatch ? 'The two passwords do not match.' : ''}
            </p>
          </div>

          <button
            type="submit"
            disabled={!canSubmit}
            className="inline-flex w-full items-center justify-center gap-2 rounded-xl bg-primary px-4 py-2.5 text-sm font-semibold text-primary-foreground transition-colors hover:bg-primary/90 disabled:opacity-50"
          >
            {busy ? <Loader2 aria-hidden className="h-4 w-4 animate-spin motion-reduce:[animation-duration:1.6s]" /> : null}
            {busy ? 'Saving' : 'Set new password'}
          </button>
        </form>
      </div>
    </div>
  )
}

Before you paste

  • Styling is Tailwind utility classes on semantic tokens (bg-card, text-muted-foreground) — it inherits your theme instead of overriding it.
  • Install: npm i lucide-react
  • Every prop has a default, so it renders standalone before you wire it up.

Where it goes

Drop it at components/auth-reset-password.tsx and import it where you need the section:

import { AuthResetPassword } from '@/components/auth-reset-password'

Customize

2 of this block’s props are simple enough to drive from here. Change them and the block below re-renders — it is the same component whose source is above, not a mock of it. Everything else it accepts is in the table underneath.

Props

Read out of the component’s own type and signature, so this cannot drift from the source below. Every prop has a default — the component renders standalone before you pass it anything.

PropTypeDefault
headingstring'Choose a new password'
minLengthnumber8
onSubmit(password: string) => Promise<void>—
classNamestring''

Not using React?

The same block rendered once to markup, wrapped as a file your framework compiles. Tailwind classes are framework-agnostic, so the design transfers intact — the behaviour does not.

This block is interactive. The markup below is its initial state with the event handlers stripped — you will need to re-wire the behaviour in your framework.

auth-reset-password.html
<!--
  New Password With Strength Meter — markup from the Hoverlab catalog.

  This is the block rendered once to HTML and wrapped as a component
  file. It is not a port of the React source: the Tailwind classes carry
  the design, which is the part that took the work, and they are the same
  in every framework.

  This block is interactive in React and the handlers are NOT here.
  Buttons, toggles and menus render in their initial state and do
  nothing until you wire them up.
-->
<div class="flex min-h-96 w-full items-center justify-center p-6 ">
  <div class="w-full max-w-sm rounded-2xl border border-border/60 bg-card/80 p-7 shadow-sm backdrop-blur">
    <div class="mb-5 inline-flex h-11 w-11 items-center justify-center rounded-xl bg-primary/15 text-primary">
      <svg xmlns="http://www.w3.org/2000/svg" width="24" height="24" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-key-round h-5 w-5" aria-hidden="true">
        <path d="M2.586 17.414A2 2 0 0 0 2 18.828V21a1 1 0 0 0 1 1h3a1 1 0 0 0 1-1v-1a1 1 0 0 1 1-1h1a1 1 0 0 0 1-1v-1a1 1 0 0 1 1-1h.172a2 2 0 0 0 1.414-.586l.814-.814a6.5 6.5 0 1 0-4-4z"></path>
        <circle cx="16.5" cy="7.5" r=".5" fill="currentColor"></circle>
      </svg>
    </div>
    <h1 class="text-2xl font-bold tracking-tight">Choose a new password</h1>
    <p class="mt-1.5 text-sm text-muted-foreground">It needs at least 8 characters. Longer beats complicated.</p>
    <form class="mt-6 space-y-4">
      <div>
        <label for="_R_0_-reset-password" class="mb-1.5 block text-sm font-medium">New password</label>
        <div class="relative">
          <input id="_R_0_-reset-password" type="password" required="" autoComplete="new-password" class="w-full rounded-xl border border-border/60 bg-background px-3.5 py-2.5 pe-11 text-sm outline-none transition-shadow focus-visible:ring-2 focus-visible:ring-primary" value="" />
          <button type="button" aria-label="Show password" aria-pressed="false" class="absolute end-1.5 top-1/2 -translate-y-1/2 rounded-lg p-2 text-muted-foreground transition-colors hover:bg-muted hover:text-foreground">
            <svg xmlns="http://www.w3.org/2000/svg" width="24" height="24" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-eye h-4 w-4" aria-hidden="true">
              <path d="M2.062 12.348a1 1 0 0 1 0-.696 10.75 10.75 0 0 1 19.876 0 1 1 0 0 1 0 .696 10.75 10.75 0 0 1-19.876 0"></path>
              <circle cx="12" cy="12" r="3"></circle>
            </svg>
          </button>
        </div>
        <div class="mt-2.5 flex items-center gap-2">
          <div aria-hidden="true" class="flex flex-1 gap-1">
            <span class="h-1 flex-1 rounded-full transition-colors bg-border/60"></span>
            <span class="h-1 flex-1 rounded-full transition-colors bg-border/60"></span>
            <span class="h-1 flex-1 rounded-full transition-colors bg-border/60"></span>
            <span class="h-1 flex-1 rounded-full transition-colors bg-border/60"></span>
          </div>
          <span class="w-16 text-end text-xs font-medium text-muted-foreground"></span>
        </div>
      </div>
      <div>
        <label for="_R_0_-reset-confirm" class="mb-1.5 block text-sm font-medium">Confirm password</label>
        <input id="_R_0_-reset-confirm" type="password" required="" autoComplete="new-password" aria-invalid="false" aria-describedby="_R_0_-reset-confirm-error" class="w-full rounded-xl border bg-background px-3.5 py-2.5 text-sm outline-none transition-shadow focus-visible:ring-2 border-border/60 focus-visible:ring-primary" value="" />
        <p id="_R_0_-reset-confirm-error" aria-live="polite" class="mt-1.5 min-h-4 text-xs text-destructive"></p>
      </div>
      <button type="submit" disabled="" class="inline-flex w-full items-center justify-center gap-2 rounded-xl bg-primary px-4 py-2.5 text-sm font-semibold text-primary-foreground transition-colors hover:bg-primary/90 disabled:opacity-50">Set new password</button>
    </form>
  </div>
</div>
  • This is rendered HTML, not a translation of the React source. The Tailwind classes carry the design and work in any framework.
  • It is one frame: the component in its initial state, with no props applied beyond the defaults.
  • This block is interactive in React — toggles, menus or form state. None of that survives here; the markup is the closed/default state and the handlers are gone. Re-wire them in your own framework.
  • Requires Tailwind, and the design tokens the classes reference (bg-card, text-muted-foreground, and so on). The template ZIPs ship a globals.css that defines them.

What each framework gets across the whole catalog — effects convert properly; this rung is markup.

For AI

The component, its props, the design tokens it expects and the command that installs it — as one prompt. Paste it into Claude, Cursor, v0 or ChatGPT and what they build around it will match the rest of the catalog instead of inventing its own system.

See the prompt

Used in these pages

Want the whole screen instead of this one section? Open a page and copy it entire.

8 more blocks in Authentication

All of them free to read, copy and install — no account, no locked tiles, no watermarked preview. The whole catalog is open, and so are the API and the CLI.

Browse Authentication

Shipping one commercially

Copying the code is free. Putting it in client work or a paid product is what Pro is for — the licence, not the access.

  • A commercial licence for everything in the catalog
  • Unlimited bundle exports, in Vue, Svelte and Tailwind
  • One payment — no subscription, nothing to renew
Pro — $79 once

More Authentication blocks

View category
Open the full page for this block

Split Signup With Proof

Registration form beside a testimonial panel, with live password rules and a proof column that drops rather than stacks on mobile.

Authentication205 lines1 dep
Open the full page for this block

One-Time Code Input

Six-box OTP entry that handles paste, backspace, arrow keys and iOS SMS autofill — the parts hand-rolled versions always miss.

Authentication184 lines1 dep
Open the full page for this block

Two-Factor Challenge

Authenticator-code prompt with a backup-code escape hatch and an opt-in trusted-device checkbox that is off by default.

Authentication148 lines1 dep
Open the full page for this block

Email-First SSO Sign-In

Email first, then whatever that domain uses. The password field is absent rather than disabled when SSO is enforced, the button names the company it redirects to, and a personal address is a normal answer instead of an error.

Authentication257 lines1 dep
Open the full page for this block

Magic Link Sign In

Passwordless sign-in that says what will land in the inbox and how long it lasts, before the address is typed.

Authentication176 linesNo deps
Open the full page for this block

Enterprise SSO Split

What SSO actually covers, written for the person who has to configure it rather than the person who asked for it.

Authentication155 linesNo deps