Configure password complexity
Currently, you can only configure how long a password should be and whether it should be entered twice.
It should be possible to specify the password complexity (minimum number of characters, special characters, numbers, letters, etc.). At the moment you need an extension for this.
-
Lukas Terfort commented
These are some requirements that are common on other sites, but not shopware. They should be added aswell for safety purposes:
The password must contain characters from the following categories:
o Upper case letters (A to Z)
Including “umlaute”
o Lower case letters (a to z)
Including “umlaute”
o Base 10 numbers (0 to 9)
o Non-alphabetic characters (for example !, $, #, %) -
Lukas Terfort commented
Add options to let the merchant choose the strength of the passwords the customers need to fulfill when creating an account.
-
Timo Reddig commented
An inadequate password policy is rated with a medium risk level by the BSI: https://www.bsi.bund.de/SharedDocs/Downloads/DE/BSI/Publikationen/DVS-Berichte/onlineshopping-plattformen.pdf?__blob=publicationFile&v=13