Defines the password complexity rules that members of a group must satisfy, such as minimum length and required character classes. Each row attaches one set of rules to a single Group. When a password is set or changed, every policy belonging to any group the profile is a member of, or has a pending membership application for, is checked, and all of them must pass. Each numeric limit is only applied when it is set and greater than zero, so leaving a limit null or zero means that rule is not enforced. Bad words are held as a comma separated list and matched case insensitively anywhere in the password, and the custom regex must match the whole password.
Group: Database Entities
Implements: Serializable, Auditable
Properties
| Property | Returns | Description |
|---|---|---|
| auditOrg | Organisation | The organisation this policy is audited against, taken from the group the policy applies to. Throws if the policy group has not been set. |
| badWords | String | Comma separated list of words that must not appear in the password. Matching is case insensitive and applies anywhere in the password, not just to whole words. Null or blank means the rule is not enforced. |
| customRegex | String | Optional extra Java regular expression that the whole password must match, not merely contain. Null or blank means the rule is not enforced. |
| id | long | Database identifier for this password policy. |
| maxRepeat | Integer | Length of a run of one repeated character that causes the password to be rejected, so a value of 3 rejects any password containing the same character three times in a row. Null or zero means the rule is not enforced. |
| minAlpha | Integer | Minimum number of alphabetic characters, of either case, the password must contain. Null or zero means the rule is not enforced. |
| minLength | Integer | Minimum total number of characters in the password. Null or zero means the rule is not enforced. |
| minLowerCase | Integer | Minimum number of lower case letters the password must contain. Null or zero means the rule is not enforced. |
| minNumeric | Integer | Minimum number of digits the password must contain. Null or zero means the rule is not enforced. |
| minUpperCase | Integer | Minimum number of upper case letters the password must contain. Null or zero means the rule is not enforced. |
| policyGroup | Group | The group this policy applies to. Every member of the group, and anyone with a pending membership application for it, must satisfy these rules when setting a password. Never null for a persisted policy. |
Methods
getId() · setId(long id) · getPolicyGroup() · setPolicyGroup(Group policyGroup) · getMinUpperCase() · setMinUpperCase(Integer minUpperCase) · getMinLowerCase() · setMinLowerCase(Integer minLowerCase) · getMinAlpha() · setMinAlpha(Integer minAlpha) · getMinNumeric() · setMinNumeric(Integer minNumeric) · getMaxRepeat() · setMaxRepeat(Integer maxRepeat) · getMinLength() · setMinLength(Integer minLength) · getBadWords() · setBadWords(String badWords) · getCustomRegex() · setCustomRegex(String customRegex) · getAuditOrg()
getId()
Returns: long
Database identifier for this password policy.
setId(long id)
Returns: void
Sets the database identifier. Normally only assigned by the persistence layer.
| Parameter | Description |
|---|---|
id | the primary key to assign |
getPolicyGroup()
Returns: Group
The group this policy applies to. Every member of the group, and anyone with a pending membership application for it, must satisfy these rules when setting a password. Never null for a persisted policy.
setPolicyGroup(Group policyGroup)
Returns: void
Sets the group this policy applies to. Required, a policy cannot be saved without one.
| Parameter | Description |
|---|---|
policyGroup | the group to attach the policy to |
getMinUpperCase()
Returns: Integer
Minimum number of upper case letters the password must contain. Null or zero means the rule is not enforced.
setMinUpperCase(Integer minUpperCase)
Returns: void
Sets the minimum number of upper case letters required. Null or zero disables the rule.
| Parameter | Description |
|---|---|
minUpperCase | the minimum upper case character count |
getMinLowerCase()
Returns: Integer
Minimum number of lower case letters the password must contain. Null or zero means the rule is not enforced.
setMinLowerCase(Integer minLowerCase)
Returns: void
Sets the minimum number of lower case letters required. Null or zero disables the rule.
| Parameter | Description |
|---|---|
minLowerCase | the minimum lower case character count |
getMinAlpha()
Returns: Integer
Minimum number of alphabetic characters, of either case, the password must contain. Null or zero means the rule is not enforced.
setMinAlpha(Integer minAlpha)
Returns: void
Sets the minimum number of alphabetic characters required. Null or zero disables the rule.
| Parameter | Description |
|---|---|
minAlpha | the minimum alphabetic character count |
getMinNumeric()
Returns: Integer
Minimum number of digits the password must contain. Null or zero means the rule is not enforced.
setMinNumeric(Integer minNumeric)
Returns: void
Sets the minimum number of digits required. Null or zero disables the rule.
| Parameter | Description |
|---|---|
minNumeric | the minimum numeric character count |
getMaxRepeat()
Returns: Integer
Length of a run of one repeated character that causes the password to be rejected, so a value of 3 rejects any password containing the same character three times in a row. Null or zero means the rule is not enforced.
setMaxRepeat(Integer maxRepeat)
Returns: void
Sets the length of a repeated character run that causes rejection. Null or zero disables the rule.
| Parameter | Description |
|---|---|
maxRepeat | the rejected repeat run length |
getMinLength()
Returns: Integer
Minimum total number of characters in the password. Null or zero means the rule is not enforced.
setMinLength(Integer minLength)
Returns: void
Sets the minimum password length. Null or zero disables the rule.
| Parameter | Description |
|---|---|
minLength | the minimum password length |
getBadWords()
Returns: String
Comma separated list of words that must not appear in the password. Matching is case insensitive and applies anywhere in the password, not just to whole words. Null or blank means the rule is not enforced.
setBadWords(String badWords)
Returns: void
Sets the comma separated list of disallowed words. Null or blank disables the rule.
| Parameter | Description |
|---|---|
badWords | the comma separated list of disallowed words |
getCustomRegex()
Returns: String
Optional extra Java regular expression that the whole password must match, not merely contain. Null or blank means the rule is not enforced.
setCustomRegex(String customRegex)
Returns: void
Sets an extra regular expression that the whole password must match. Null or blank disables the rule. An expression that does not compile will cause password validation to fail at runtime.
| Parameter | Description |
|---|---|
customRegex | the custom regular expression |
getAuditOrg()
Returns: Organisation
The organisation this policy is audited against, taken from the group the policy applies to. Throws if the policy group has not been set.