Random password generator using Ajax in ASP.Net MVC

You can download the project from here : Download MVCPasswordExample 

As title says when user click a button it send ajax request to controller
$.post('@Url.Content("~/Home/GeneratePassword/")' ...
and returns Json with new 8 character password.


public class RegisterModel
        [Display(Name = "User name")]
        public string UserName { get; set; }

        [Display(Name = "Email address")]
        public string Email { get; set; }

        [StringLength(100, ErrorMessage = "The {0} must be at least {2} characters long.", MinimumLength = 6)]
        [Display(Name = "Password")]
        public string Password { get; set; }

        [Display(Name = "Confirm password")]
        [Compare("Password", ErrorMessage = "The password and confirmation password do not match.")]
        public string ConfirmPassword { get; set; }


    ViewBag.Title = "Home Page";

@using MVCPasswordExample.Models
@model RegisterModel

    $(document).ready(function () {
        $('#updateprofile').click(function () {


        $('#autogenerate').click(function () {
            $.post('@Url.Content("~/Home/GeneratePassword/")', function (data) {

                $('#password, #confirmpassword').attr("value", data.password);





<table style="margin-top:100px;width:40%">
 <th colspan="3">Change Password</th>

      <td>@Html.LabelFor(m => m.Password)
     <td style="width:20%">
         @Html.TextBox("password", null, new { @class = "search_field", @id = "password", @Value = "" })
      <td><input type="button" id="autogenerate" value="Auto generate" class="submit_button" /></td>
         @Html.LabelFor(m => m.ConfirmPassword)
     <td class="confirm" colspan="2">
          @Html.TextBox("confirmpassword", null, new { @class = "search_field", @id = "confirmpassword" })




        public JsonResult GeneratePassword()
           var pass = Guid.NewGuid().ToString().Substring(0, 8);

            return Json(new { password = pass });


  1. Cool! I think we had this discussion before.

    The problem with your code is that you are missing the fact that substrings of GUIDS are not unique. This is an issue because you are dealing with passwords thought. What happens here is that you will come up with duplicated values (which should not be a recommend scenario for a password).

    I wrote a blog post about this issue here http://blog.michaelhidalgo.info/2013/08/a-poc-to-verify-that-guids-substrings.html

    While I understand that this is a cool demo on how to use Ajax and ASP.NET MVC, I think it is worth to make that password stronger. Or at least to put a note on why substrings of GUIDS are not unique.

    So others readers can see a potential issue with it.


