Skip to content

Conversation

@Rany0101
Copy link
Contributor

Summary

Account API: follow the security policy of password and blocklist

Account API: Follow password policy and email blocklist
@Rany0101 Rany0101 enabled auto-merge November 10, 2025 08:29
Copy link
Contributor

Copilot AI left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull Request Overview

This PR enhances password policy documentation by adding comprehensive guidance on how password policies are enforced and checked across different APIs in Logto.

Key changes:

  • Added new "Password compliance check" section explaining how to audit existing passwords against current policy
  • Clarified that password policies apply differently to end-user flows (enforced) vs. admin operations (exempt)
  • Enhanced email blocklist documentation with more specific use case scenarios

Reviewed Changes

Copilot reviewed 4 out of 4 changed files in this pull request and generated 4 comments.

File Description
docs/user-management/manage-users.mdx Adds password compliance check section to help administrators verify existing users' passwords against current policy
docs/security/password-policy.mdx Adds introductory explanation of policy enforcement across different APIs and includes related resource links
docs/security/blocklist.md Expands blocklist restriction details with specific sign-up and linking scenarios
docs/end-user-flows/account-settings/by-account-api.mdx Adds tip boxes clarifying that password and email operations via Account API enforce current policies

💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.

@cloudflare-workers-and-pages
Copy link

cloudflare-workers-and-pages bot commented Nov 10, 2025

Deploying logto-docs-tutorials with  Cloudflare Pages  Cloudflare Pages

Latest commit: 4b7fcdb
Status: ✅  Deploy successful!
Preview URL: https://47c76d8c.logto-docs-tutorials.pages.dev
Branch Preview URL: https://rany-account-api-security-po.logto-docs-tutorials.pages.dev

View logs

Rany0101 and others added 3 commits November 10, 2025 16:35
Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com>
Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com>
Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com>
@cloudflare-workers-and-pages
Copy link

cloudflare-workers-and-pages bot commented Nov 10, 2025

Deploying logto-docs with  Cloudflare Pages  Cloudflare Pages

Latest commit: 4b7fcdb
Status: ✅  Deploy successful!
Preview URL: https://d5fb48a3.logto-docs.pages.dev
Branch Preview URL: https://rany-account-api-security-po.logto-docs.pages.dev

View logs

@Rany0101 Rany0101 merged commit f12f3f9 into master Nov 10, 2025
19 checks passed
@Rany0101 Rany0101 deleted the rany-account-api-security-policy branch November 10, 2025 08:52
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Development

Successfully merging this pull request may close these issues.

3 participants