Skip to content

review password policy #2307

@davepacheco

Description

@davepacheco

We should decide if we want the public API to enforce any particular policy regarding password security (e.g., minimum length, characters used, etc.). I have no particular opinion on this but it seems like something we should decide explicitly before MVP.

References:

// TODO-security If we want to apply password policy rules, this seems
// like the place. We presumably want to also document them in the
// OpenAPI schema below.

// TODO-doc If we apply password strength rules, they should
// presumably be documented here.

Metadata

Metadata

Assignees

No one assigned

    Labels

    securityRelated to security.

    Type

    No type

    Projects

    No projects

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions