Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[Issue] Increase minimum password length for admin user #39327

Open
4 of 5 tasks
m2-assistant bot opened this issue Nov 5, 2024 · 7 comments · May be fixed by #39319
Open
4 of 5 tasks

[Issue] Increase minimum password length for admin user #39327

m2-assistant bot opened this issue Nov 5, 2024 · 7 comments · May be fixed by #39319
Assignees
Labels
Area: Security Component: Security feature request Issue: Confirmed Gate 3 Passed. Manual verification of the issue completed. Issue is confirmed Priority: P2 A defect with this priority could have functionality issues which are not to expectations. Progress: PR in progress Reported on 2.4.x Indicates original Magento version for the Issue report. Reproduced on 2.4.x The issue has been reproduced on latest 2.4-develop branch

Comments

@m2-assistant
Copy link

m2-assistant bot commented Nov 5, 2024

This issue is automatically created based on existing pull request: #39319: Increase minimum password length for admin user


Description (*)

PCI 4.0 requires a minimal password length of 12 characters, so it has to be changed from 7 to 12.

Manual testing scenarios (*)

  1. Change password of an existing admin account.
  2. It should fail to change the password if less than 12 characters are used.

Contribution checklist (*)

  • Pull request has a meaningful description of its purpose
  • All commits are accompanied by meaningful commit messages
  • All new or changed code is covered with unit/integration tests (if applicable)
  • README.md files for modified modules are updated and included in the pull request if any README.md predefined sections require an update
  • All automated tests passed successfully (all builds are green)
@m2-assistant m2-assistant bot linked a pull request Nov 5, 2024 that will close this issue
6 tasks
@github-project-automation github-project-automation bot moved this to Ready for Confirmation in Issue Confirmation and Triage Board Nov 5, 2024
@m2-community-project m2-community-project bot added the Priority: P2 A defect with this priority could have functionality issues which are not to expectations. label Nov 5, 2024
@engcom-Bravo engcom-Bravo self-assigned this Nov 5, 2024
Copy link
Author

m2-assistant bot commented Nov 5, 2024

Hi @engcom-Bravo. Thank you for working on this issue.
In order to make sure that issue has enough information and ready for development, please read and check the following instruction: 👇

  • 1. Verify that issue has all the required information. (Preconditions, Steps to reproduce, Expected result, Actual result).
  • 2. Verify that issue has a meaningful description and provides enough information to reproduce the issue.
  • 3. Add Area: XXXXX label to the ticket, indicating the functional areas it may be related to.
  • 4. Verify that the issue is reproducible on 2.4-develop branch
    Details- If the issue is reproducible on 2.4-develop branch, please, add the label Reproduced on 2.4.x.
    - If the issue is not reproducible, add your comment that issue is not reproducible and close the issue and stop verification process here!
  • 5. Add label Issue: Confirmed once verification is complete.
  • 6. Make sure that automatic system confirms that report has been added to the backlog.

@engcom-Bravo
Copy link
Contributor

Hi @torhoehn,

Thanks for your reporting and collaboration.

As per the Magento devdocs https://experienceleague.adobe.com/en/docs/commerce-operations/installation-guide/tutorials/admin The password must be at least 7 characters in length and must include at least one alphabetic and at least one numeric character

Hence we are considering this as a improvement to proceed further marking this as Feature Request.

Thanks.

@torhoehn
Copy link
Contributor

torhoehn commented Nov 7, 2024

@engcom-Bravo What does that mean in terms of processing this PR?

@torhoehn
Copy link
Contributor

torhoehn commented Nov 7, 2024

@engcom-Bravo I created a PR for the docs as well: AdobeDocs/commerce-operations.en#136

@glo24157
Copy link
Contributor

Confirming issue for further processing.

@engcom-Hotel engcom-Hotel added the Issue: Confirmed Gate 3 Passed. Manual verification of the issue completed. Issue is confirmed label Jan 28, 2025
@engcom-Hotel engcom-Hotel added Component: Security Reproduced on 2.4.x The issue has been reproduced on latest 2.4-develop branch Area: Security labels Jan 28, 2025
@github-jira-sync-bot
Copy link

✅ Jira issue https://jira.corp.adobe.com/browse/AC-13826 is successfully created for this GitHub issue.

Copy link
Author

m2-assistant bot commented Jan 28, 2025

✅ Confirmed by @engcom-Hotel. Thank you for verifying the issue.
Issue Available: @engcom-Hotel, You will be automatically unassigned. Contributors/Maintainers can claim this issue to continue. To reclaim and continue work, reassign the ticket to yourself.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
Area: Security Component: Security feature request Issue: Confirmed Gate 3 Passed. Manual verification of the issue completed. Issue is confirmed Priority: P2 A defect with this priority could have functionality issues which are not to expectations. Progress: PR in progress Reported on 2.4.x Indicates original Magento version for the Issue report. Reproduced on 2.4.x The issue has been reproduced on latest 2.4-develop branch
Projects
Status: Ready for Grooming
Development

Successfully merging a pull request may close this issue.

5 participants