Skip to content

Commit b5eed24

Browse files
Merge pull request #35 from NicolaiSoeborg/patch-1
password auth: Avoid mandatory password rotation
2 parents c4f012f + 1dce38d commit b5eed24

File tree

1 file changed

+1
-0
lines changed

1 file changed

+1
-0
lines changed

pages/password-authentication.md

Lines changed: 1 addition & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -138,5 +138,6 @@ If you need to keep the username or email private, make sure you do not leak suc
138138
## Other considerations
139139

140140
- Do not prevent users from copy-pasting passwords as it discourages users from using password managers.
141+
- Do not require users to change passwords periodically.
141142
- Ask for the current password when a user attempts to change their password.
142143
- [Open redirect](/open-redirect).

0 commit comments

Comments
 (0)