One password rule everywhere
Every place that sets a password now applies the same rule: at least 8 characters, including a lowercase letter, an uppercase letter and a number. A symbol is welcome but does not replace a number.
- The sign-up, set-password, reset-password and change-password forms all check the rule before you submit, so a password the server would refuse can no longer look acceptable.
- The API returns a single message for every violation: "Password must be at least 8 characters and include a lowercase letter, an uppercase letter and a number".
- If setting the password fails after your verification code was accepted, you can retry without requesting a new code.
- The sign-up password form now includes your email as the username, so your browser's save-password prompt stores a complete login.