Skip to main content

2 posts tagged with "api"

View All Tags

One password rule everywhere

Every place that sets a password now applies the same rule: at least 8 characters, including a lowercase letter, an uppercase letter and a number. A symbol is welcome but does not replace a number.

  • The sign-up, set-password, reset-password and change-password forms all check the rule before you submit, so a password the server would refuse can no longer look acceptable.
  • The API returns a single message for every violation: "Password must be at least 8 characters and include a lowercase letter, an uppercase letter and a number".
  • If setting the password fails after your verification code was accepted, you can retry without requesting a new code.
  • The sign-up password form now includes your email as the username, so your browser's save-password prompt stores a complete login.

Email signup: verify-code now returns a setupToken

POST /api/auth/verify-code (and the emailed verification link) now returns a single-use setupToken, valid for 30 minutes. It proves that the person setting the password owns the email address.

Pass it to POST /api/auth/set-password together with the email and password:

{ "email": "you@example.com", "password": "<choose one>", "setupToken": "<from verify-code>" }

What you need to do. If you script or automate signup (agents, CLI-style flows), send the token from the verify step. Today a request without it still succeeds, so nothing breaks yet. We will require it after a notice period, and we will announce the date here.

Accounts that sign in with Google or through the Gluo portal cannot have a password set through this endpoint.