• Resolved dtamajon

    (@dtamajon)


    Hi,

    I’m testing the module and there is a strange behavior. After I create an account, if I try to login I get the message “Due to site rules, a strong password is required”.

    Shouldn’t be a validation while creating the user to avoid changing the password?

    Thank you!

Viewing 10 replies - 1 through 10 (of 10 total)
  • Plugin Support chandelierrr

    (@shanedelierrr)

    Hi @dtamajon, thank you for reaching out. Could you please confirm if the password entered was indicated as strong during account creation? If so, the password might pass the WP strong password meter but not the iThemes Security password meter. You can either choose a stronger password or disable the feature. If you can’t access your site, manually disable iThemes Security via FTP by renaming its directory to bypass the password requirement. Please let me know how it goes.

    Thread Starter dtamajon

    (@dtamajon)

    Hi, I confirm the password entered was indicated as strong during account creation.

    When you say “choose a stronger password” you mean that I have to introduce a stronger password during account creation?

    When you seay “disable the feature” you mean the iThemes Security feature?

    Thank you

    Plugin Support chandelierrr

    (@shanedelierrr)

    @dtamajon yes, kindly choose a stronger password during account creation. iTSec uses the zxcvbn password measurement, which is stricter. You can read more about how that works here. As for disabling the feature, I’m referring to the Strong Passwords feature of iTSec. I hope this helps!

    Thread Starter dtamajon

    (@dtamajon)

    Hi, how do I force a stronger password during creation? This is an e-commerce, so I cannot create personally a password for each customer. It should work automatically.

    If I disable Strong Passwords feature, then how can I solve may problem: force users to use a strong password?

    Thank you for your time!

    Plugin Support chandelierrr

    (@shanedelierrr)

    @dtamajon will you please share the password for the test account you created that shows the “Due to site rules, a strong password is required” message?

    Thread Starter dtamajon

    (@dtamajon)

    What matters the password if the registration process allows me to use any password? Why not force from the beginning to the user to use a strong password?

    I can use “Prova2023!” which will ask to change the password for a more secure one on the next login, or “ProvaForta2023!” which will not ask.

    The problem is not what I know… the problem is what we let do to the customers and how odd is the process to establish a strong password.

    Plugin Support chandelierrr

    (@shanedelierrr)

    Hi @dtamajon, apologies for the delayed response. Could you please confirm that the “Customers” role, as well as other user roles inside the iTSec User Groups settings, have the Strong Passwords enabled?

    Thread Starter dtamajon

    (@dtamajon)

    HI! Thank you for your follow up!

    I confirm that “Customers” role has “Strong Passwords” enabled. I have checked all roles, and all them have “Strong Passwords” enabled.

    Plugin Support chandelierrr

    (@shanedelierrr)

    Hi @dtamajon, thank you for the update. I tested on my test sites with the free and pro version of the plugin, and I can replicate the same behavior. I believe this is because the feature is only set up to work with the default WordPress login/register pages presently. A workaround that I could recommend is redirecting the Register button to /wp-login.php?action=register so that the plugin will apply the Strong Passwords rule upon registration. I hope this helps!

    Plugin Support chandelierrr

    (@shanedelierrr)

    Hi @dtamajon, I hope the information provided helped. Since we haven’t received a response, I’ll mark this post resolved. If you still need some assistance, feel free to open a new support topic, and we’d be happy to assist. Thank you!

Viewing 10 replies - 1 through 10 (of 10 total)
  • The topic ‘Due to site rules, a strong password is required’ is closed to new replies.