README.md in devise_zxcvbn-1.0.0 vs README.md in devise_zxcvbn-1.1.0

- old
+ new

@@ -1,10 +1,10 @@ # devise_zxcvbn [![Gem Version](https://badge.fury.io/rb/devise_zxcvbn.png)](http://badge.fury.io/rb/devise_zxcvbn) -Plugin for devise to reject weak passwords, using [zxcvbn-ruby](https://github.com/envato/zxcvbn-ruby) which is a ruby port of [zxcvbn: realistic password strength estimation](https://tech.dropbox.com/2012/04/zxcvbn-realistic-password-strength-estimation/). +Plugin for devise to reject weak passwords, using [zxcvbn-ruby](https://github.com/envato/zxcvbn-ruby) which is a ruby port of [zxcvbn: realistic password strength estimation](https://tech.dropbox.com/2012/04/zxcvbn-realistic-password-strength-estimation/). The user's password will be rejected if the score is below 4 by default. It also uses the email as user input to zxcvbn, to downscore passwords containing the email. The scores 0, 1, 2, 3 or 4 are given when the estimated crack time (seconds) is less than 10**2, 10**4, 10**6, 10**8, Infinity. ## Installation @@ -15,10 +15,10 @@ ## Devise Configuration class User < ActiveRecord::Base - devise :database_authenticatable, :zxcvbnable + devise :database_authenticatable, :validatable, :zxcvbnable end ### Default parameters A score of less than 3 is not recommended.