strong password policies
Hi everyone,
I'm looking for some advice on enforcing strong password policies in FluentCommunity.
I'm using FluentCommunity Pro together with FluentAuth, and my users register through the native FluentCommunity signup form.
I'd like to require strong passwords for all new users, for example:
- Minimum 12 characters
- At least one uppercase letter
- At least one lowercase letter
- At least one number
- At least one special character
I couldn't find any built-in setting for password policies in either FluentCommunity or FluentAuth.
Has anyone implemented this successfully?
- Is there a built-in option that I missed?
- Is there an official hook or filter to validate password strength during registration?
- Or are you using a custom solution?
I'd love to hear how others are handling this.
Thanks!
The first thing that came to my mind if you want to strengthen your policies is enable 2FA in auth for the user role you assign to your members.
Jorge de los ReyesΒ I did, but a lot of people is still use passowrd123456 and I would like to block this. moreover F2A with e-mail is easily hacked because the same people that use that kind of password usually use them for email too so for the hacker is a piece of cake to hacker their email...the strongest F2A is with google authenticator or similar app
Thanks for the post, I will forward this post to our team.
Tawsif Ahmed RiyadΒ thank you
Tawsif Ahmed RiyadΒ please make this suggestion an option only... I have password fatigue and I often stop signing up just because they ask for too many rules when setting my password up. I can't express how much that enrages me! For governmental/banking portals, it only makes sense. For anything else, it's just too much!
AS W, we will review the feature request, and if it is approved by our team, it will be optional, as there are split opinions; some want an easy process, while others want tight configuration.
AS WΒ I agree