Overview
Znode enforces a stronger and standardized password policy across all applications that create, update, reset, or manage user passwords. The enhancement improves account security by requiring stronger passwords, preventing the use of personal identifiers within passwords, and ensuring consistent validation across all password-related workflows.
The password policy applies to:
- Admin Console
- API integrations
- Storefront
- Page Builder
- Commerce Portal
The policy does not apply to BStore. Existing user passwords remain valid and are not affected until a password is changed or reset.
Password Policy Requirements
All newly created or modified passwords must meet the following requirements:
| Requirement | Value |
|---|---|
| Minimum Length | 12 Characters |
| Maximum Length | 128 Characters |
| Uppercase Letter | Required |
| Lowercase Letter | Required |
| Number | Required |
| Special Character | Required |
| Username in Password | Not Allowed |
| Email Address in Password | Not Allowed |
Valid Password Example
MySecure@Password2026
Invalid Password Examples
| Password | Reason |
|---|---|
| Password123 | Missing special character |
| johnsmith123! | Contains username |
| user@email.com123! | Contains email address |
Password validation is case-insensitive when checking for usernames and email addresses. A password containing any variation of the username or email address is rejected.
Use Case 1: Create a New User Account
Administrators creating users in the Admin Console or Commerce Portal must provide a password that complies with the updated password policy.
Steps
- Navigate to the user creation page.
- Enter the required user information.
- Enter a password that meets all password policy requirements.
- Save the user record.
Expected Outcome
- The user account is created successfully when all password requirements are met.
- If the password fails validation, account creation is prevented and an error message is displayed.
Use Case 2: Register a Customer Account on the Storefront
Customer registration validates passwords using the same centralized password policy applied throughout the platform.
Steps
- Open the registration page on the Storefront.
- Enter the registration details.
- Enter a password that satisfies all complexity requirements.
- Submit the registration form.
Expected Outcome
- Registration completes successfully when the password is valid.
- Registration is prevented when the password does not meet the required standards.
Use Case 3: Change an Existing Password
Password changes across the Admin Console, Storefront, and Commerce Portal use the updated validation rules.
Steps
- Navigate to the Change Password page.
- Enter the current password.
- Enter a new password that meets all password policy requirements.
- Confirm the new password.
- Submit the request.
Expected Outcome
- The password is updated successfully when validation passes.
- The request is rejected if the new password violates any policy rule.
Updated Validation Behavior
| Field | Validation |
|---|---|
| Current Password | Required Only |
| New Password | Full Password Policy Validation |
| Confirm Password | Must Match New Password |
This behavior allows existing users with older passwords to change credentials without requiring the current password to meet the new complexity standards.
Use Case 4: Reset a Forgotten Password
Forgot Password and Reset Password workflows enforce the enhanced password policy.
Steps
- Initiate the password reset process.
- Open the password reset page using the reset link.
- Enter a new password.
- Confirm the password.
- Submit the request.
Expected Outcome
- Password reset completes successfully when the password meets all requirements.
- Reset requests are rejected when validation fails.
Use Case 5: Administrative Password Management
Administrative password-related functions enforce the same validation rules used throughout the platform.
Supported Functions
- Reset Password
- Reset Administrator Password
- Create User
- Convert Buyer to Administrator
- Commerce Portal User Creation
All workflows follow identical password validation requirements.
Password Expiration Notifications
A password expiration notification is available for Admin Console users.
When the Notification Appears
The notification displays after login when the password expiration date is within the next seven days.
Notification Message
Your password expires in N days. Please change it soon.
Behavior
- Displays after successful login.
- Appears once after login.
- Does not block access.
- Does not require an immediate password change.
- Existing password expiration policies remain unchanged.
Validation Messages
Password Complexity Error
Password must be at least 12 characters long and include uppercase and lowercase letters, at least one number, and at least one special character.
Username or Email Validation Error
Your password must not contain your username or email address.
Existing User Impact
Existing users are not required to change their current passwords as part of this enhancement.
Unchanged Behavior
- Existing passwords continue to function.
- Login behavior remains unchanged.
- Current password expiration processes remain unchanged.
- Password history enforcement remains unchanged.
- No forced password reset is introduced.
Password History Policy
The existing password reuse restriction remains active.
Users cannot reuse any of their previous four passwords.
Common Validation Scenarios
| Scenario | Result |
|---|---|
| Password contains username | Rejected |
| Password contains email address | Rejected |
| Password contains fewer than 12 characters | Rejected |
| Password is missing an uppercase letter | Rejected |
| Password is missing a lowercase letter | Rejected |
| Password is missing a number | Rejected |
| Password is missing a special character | Rejected |
| Password meets all requirements | Accepted |
Important Notes
- Password validation is enforced centrally through the API layer and cannot be bypassed through direct API requests.
- System-generated passwords comply with the same password policy requirements as user-created passwords.
- All supported applications display consistent password validation behavior.
- BStore is not impacted by this enhancement.
- Password expiration notifications apply only to Admin Console users.
Related Areas
The password policy enhancement affects the following business processes:
- User Registration
- User Management
- Password Changes
- Password Resets
- Administrative User Creation
- Commerce Portal User Administration
- Password Expiration Notifications
- API-based Password Operations