Password Policy Enforcement Across Admin Console, Storefront, API, and Commerce Portal

Overview

Znode enforces a stronger and standardized password policy across all applications that create, update, reset, or manage user passwords. The enhancement improves account security by requiring stronger passwords, preventing the use of personal identifiers within passwords, and ensuring consistent validation across all password-related workflows.

The password policy applies to:

  • Admin Console
  • API integrations
  • Storefront
  • Page Builder
  • Commerce Portal

The policy does not apply to BStore. Existing user passwords remain valid and are not affected until a password is changed or reset.

Password Policy Requirements

All newly created or modified passwords must meet the following requirements:

RequirementValue
Minimum Length12 Characters
Maximum Length128 Characters
Uppercase LetterRequired
Lowercase LetterRequired
NumberRequired
Special CharacterRequired
Username in PasswordNot Allowed
Email Address in PasswordNot Allowed

Valid Password Example

MySecure@Password2026

Invalid Password Examples

PasswordReason
Password123Missing special character
johnsmith123!Contains username
user@email.com123!Contains email address

Password validation is case-insensitive when checking for usernames and email addresses. A password containing any variation of the username or email address is rejected.

Use Case 1: Create a New User Account

Administrators creating users in the Admin Console or Commerce Portal must provide a password that complies with the updated password policy.

Steps

  1. Navigate to the user creation page.
  2. Enter the required user information.
  3. Enter a password that meets all password policy requirements.
  4. Save the user record.

Expected Outcome

  • The user account is created successfully when all password requirements are met.
  • If the password fails validation, account creation is prevented and an error message is displayed.

Use Case 2: Register a Customer Account on the Storefront

Customer registration validates passwords using the same centralized password policy applied throughout the platform.

Steps

  1. Open the registration page on the Storefront.
  2. Enter the registration details.
  3. Enter a password that satisfies all complexity requirements.
  4. Submit the registration form.

Expected Outcome

  • Registration completes successfully when the password is valid.
  • Registration is prevented when the password does not meet the required standards.

Use Case 3: Change an Existing Password

Password changes across the Admin Console, Storefront, and Commerce Portal use the updated validation rules.

Steps

  1. Navigate to the Change Password page.
  2. Enter the current password.
  3. Enter a new password that meets all password policy requirements.
  4. Confirm the new password.
  5. Submit the request.

Expected Outcome

  • The password is updated successfully when validation passes.
  • The request is rejected if the new password violates any policy rule.

Updated Validation Behavior

FieldValidation
Current PasswordRequired Only
New PasswordFull Password Policy Validation
Confirm PasswordMust Match New Password

This behavior allows existing users with older passwords to change credentials without requiring the current password to meet the new complexity standards.

Use Case 4: Reset a Forgotten Password

Forgot Password and Reset Password workflows enforce the enhanced password policy.

Steps

  1. Initiate the password reset process.
  2. Open the password reset page using the reset link.
  3. Enter a new password.
  4. Confirm the password.
  5. Submit the request.

Expected Outcome

  • Password reset completes successfully when the password meets all requirements.
  • Reset requests are rejected when validation fails.

Use Case 5: Administrative Password Management

Administrative password-related functions enforce the same validation rules used throughout the platform.

Supported Functions

  • Reset Password
  • Reset Administrator Password
  • Create User
  • Convert Buyer to Administrator
  • Commerce Portal User Creation

All workflows follow identical password validation requirements.

Password Expiration Notifications

A password expiration notification is available for Admin Console users.

When the Notification Appears

The notification displays after login when the password expiration date is within the next seven days.

Notification Message

Your password expires in N days. Please change it soon.

Behavior

  • Displays after successful login.
  • Appears once after login.
  • Does not block access.
  • Does not require an immediate password change.
  • Existing password expiration policies remain unchanged.

Validation Messages

Password Complexity Error

Password must be at least 12 characters long and include uppercase and lowercase letters, at least one number, and at least one special character.

Username or Email Validation Error

Your password must not contain your username or email address.

Existing User Impact

Existing users are not required to change their current passwords as part of this enhancement.

Unchanged Behavior

  • Existing passwords continue to function.
  • Login behavior remains unchanged.
  • Current password expiration processes remain unchanged.
  • Password history enforcement remains unchanged.
  • No forced password reset is introduced.

Password History Policy

The existing password reuse restriction remains active.

Users cannot reuse any of their previous four passwords.

Common Validation Scenarios

ScenarioResult
Password contains usernameRejected
Password contains email addressRejected
Password contains fewer than 12 charactersRejected
Password is missing an uppercase letterRejected
Password is missing a lowercase letterRejected
Password is missing a numberRejected
Password is missing a special characterRejected
Password meets all requirementsAccepted

Important Notes

  • Password validation is enforced centrally through the API layer and cannot be bypassed through direct API requests.
  • System-generated passwords comply with the same password policy requirements as user-created passwords.
  • All supported applications display consistent password validation behavior.
  • BStore is not impacted by this enhancement.
  • Password expiration notifications apply only to Admin Console users.

Related Areas

The password policy enhancement affects the following business processes:

  • User Registration
  • User Management
  • Password Changes
  • Password Resets
  • Administrative User Creation
  • Commerce Portal User Administration
  • Password Expiration Notifications
  • API-based Password Operations

Did you find it helpful? Yes No

Send feedback
Sorry we couldn't be helpful. Help us improve this article with your feedback.