The password rules, stated so a person does not have to guess them.
These MIRROR the identity server's own validator (PasswordManager .validatePassword): 8–128 characters with a lowercase letter, an
uppercase letter, a digit and a special character. Showing them up front
is the point — a form that only says "weak" after the fact makes the user
guess which rule they missed, and a strength score computed from
different criteria than the server enforces can read "Good" for a
password the server then rejects.
minLength is a parameter because an organisation can raise it in its
identity settings; the other rules are fixed by the validator.
The password rules, stated so a person does not have to guess them.
These MIRROR the identity server's own validator (
PasswordManager .validatePassword): 8–128 characters with a lowercase letter, an uppercase letter, a digit and a special character. Showing them up front is the point — a form that only says "weak" after the fact makes the user guess which rule they missed, and a strength score computed from different criteria than the server enforces can read "Good" for a password the server then rejects.minLengthis a parameter because an organisation can raise it in its identity settings; the other rules are fixed by the validator.