A password-change page belongs inside the authenticated member area and should re-check that the user is signed in before processing the update.
<!-- #include file="menu.asp" --><form method="post" action="pwck.asp">
<label for="password">New password</label>
<input type="password" id="password" name="password" autocomplete="new-password">
<label for="password2">Confirm new password</label>
<input type="password" id="password2" name="password2" autocomplete="new-password">
<button type="submit">Change password</button>
</form>Do not impose an unnecessary letters-and-numbers-only rule. Passwords should support long passphrases and a broad character set. Apply a sensible maximum length based on the chosen hashing library.
If IsEmpty(Session("userid")) Then Response.Redirect "lg-login.php"
password = Request.Form("password")
password2 = Request.Form("password2")
If password <> password2 Then
Response.Write "The passwords do not match."
Response.End
End If
' newHash = PasswordHasher.Hash(password)
' Update password_hash with an ADODB.Command parameter.The actual hash operation is deliberately shown as an integration point because Classic ASP/VBScript has no built-in modern password-hashing API. Use a vetted Argon2id, bcrypt or PBKDF2 implementation/component and store only the resulting password hash.
For a higher-risk application, ask the user to re-authenticate before changing a password and consider invalidating other active sessions after the change.
Author & Instructor at plus2net
I write and maintain practical tutorials on Python, PHP, SQL, JavaScript, HTML, jQuery, and web development at plus2net. The tutorials focus on clear explanations, working examples, and code that readers can test and adapt while learning.