A user ID can be checked against the exact character set and length your application accepts. This example allows only ASCII letters and digits and requires between 3 and 8 characters.
Dim re
Set re = New RegExp
Configure the pattern and test the submitted value:
Dim userId, isValid
Set re = New RegExp
re.Pattern = "^[A-Za-z0-9]{3,8}$"
re.IgnoreCase = True
re.Global = False
userId = "a234f678"
isValid = re.Test(userId)
Response.Write isValid
Examples that pass this specific rule:
A234f678, a23, a2345f, a2345f6
Examples that fail:
A2, a2345f6789, a23*5, a234f5/6
This is an application-specific user-ID rule, not a universal requirement. If your site legitimately supports underscores, hyphens, Unicode characters, or longer identifiers, define a pattern that matches those requirements instead.
Password validation should not be treated as the same problem as user-ID validation. Do not restrict passwords to only letters and numbers; modern password policies should allow broad character choices and passwords must be stored using an appropriate password-hashing system rather than reversible/plain-text storage.
Author & Instructor at plus2net
I write and maintain practical tutorials on Python, PHP, SQL, JavaScript, HTML, jQuery, and web development at plus2net. The tutorials focus on clear explanations, working examples, and code that readers can test and adapt while learning.