Question about passwords

Operating system

Linux

Joplin version

3.7.2

What issue do you have?

Is there any way to turn down the requirements on the passwords? I have a secure environment I run in (just myself from my Linux system and from my mobile app on my Android phone) and I really don't want to have to remember special passwords for this one app. I have variants of a standard password that I use for all of my homelab apps and Joplin rejects the password. Same goes for changing the admin PW. I like Joplin a lot and have been using it on my phone for 6 months or so but this is killing me. Please advise. Thanks

@ronch808 welcome to the forum.

From your question and the version number quoted I assume that you are referring to Joplin Server.

Can I ask why you need to repeatedly log into the server? There is little to administer from the server web interface and the Joplin clients remember the password in order to sync.

Just trying to get a better picture of what the problem is so the devs can decide if they should look into this.

WordPress also doesn't allow it to log in without a password. I think this is the industry standard, if you want to change it, then it's open source you can change the code however you want, I'm sure an SI will help you.

Hi, Thanks for the reply. So my issue is having to remember another special PW as to using my naming scheme to all of my homelab containers. I agree that the admin login for me will be rare which does help and yes I use a password manager, again to make things easier. It's a convention issue for me. Like where are the password rules written down? I've tried 4 variants and none of them work since I don't know what the rules are. It's just very frustrating. I have added myself as a user which was the first thing to do but having the password warnings happening at each login is frustrating. Thanks for listening. I know a number of homelab apps have en environment setting to either eliminate or easy password restrictions. Something like that would help in this case. Also, publishing the password rules would be another.

For popular apps, Enpass (my Password Manager) tells me what the password requirements are. I have no idea where it gets it from, but that is beside your main issue. When I notice that a site will not accept certain characters i password, I tell Enpass to exclude them next time it generates a random password string. Eventually I'll have excluded enough characters to know which one were the invalid ones.'
If the password string that can now be accepted is considered weak, then I'll tinker som more and start to add special characters again, to see when it fails again. Eventually I've made my own list and I'll note it down for that site, in case I need to change password here in the future.

I think it would also help if you could tell why the developer should implement this change versus you saving another password to your manager and copying it into a field whenever needed.
I am not trying to be rude, just seeing it from the perspective of this one person project :slight_smile: