Open jeffcorpuz opened 6 years ago
The issue title contains "OAuth/Hydra" but password policies are completely handled by the "Identity Provider", implemented by Reaction by the Meteor auth package. Hydra only issues tokens upon confirmation of the user login.
@ticean thanks for the clear up! edited the title to reflect it properly.
Feature Request Description
There is no standard password strength checklist or a place where you can enable the strength of a password when creating accounts and/or resetting passwords.
i.e You can create an account with a password with one character.
Possible Solution
Add the capability for an administrator to set-up minimum password requirements. Add a reasonable default password requirement.
Examples:
Source: https://en.wikipedia.org/wiki/Password_strength