Accessible Authentication (Minimum)
Authentication processes must not depend on cognitive function tests (memorizing characters, transcribing puzzles) without an alternative.
What it requires
Logging in by typing a memorized password is a cognitive function test. WCAG 2.2 SC 3.3.8 requires that a working alternative exist — typically a copy-paste-friendly password input, browser autofill compatibility, or an alternative authentication method (passkey, magic link, OAuth).
CAPTCHA and "type the characters in this image" puzzles are also cognitive function tests. Sites must provide an accessible alternative (audio CAPTCHA, no-CAPTCHA reCAPTCHA, or an entirely different verification method).
Common Shopify failure
Customer-account login form blocks paste on the password field. Custom signup flow with image-CAPTCHA and no audio alternative.
How to fix it
Remove `onpaste="return false"` and `autocomplete="off"` on password fields. Replace image CAPTCHA with reCAPTCHA v3 or hCaptcha (which include audio).
Merchant QA checklist
- Scan the storefront page where this pattern appears: product pages, collection pages, cart drawer, customer-account pages, and any landing page built with theme sections.
- Confirm the issue is fixed in the rendered browser output, not only in the Liquid file. Shopify section settings, app blocks, and third-party scripts can reintroduce the same 3.3.8 failure after a theme edit.
- Re-test the affected component with keyboard navigation and a screen-reader accessibility tree before publishing the theme, especially when the fix changes markup or ARIA attributes.
How AccessComply handles it
AccessComply uses automated rules to check supported patterns in the pages reached during a scan. Some WCAG requirements need human judgment, assistive-technology testing, or access to third-party content and cannot be established by an automated scan. This criterion is generally treated as a pattern that may have a supported suggested fix. If the app can safely match the issue to supported source code, the merchant must review and approve the suggested change before anything is written, and the result is checked afterward. Otherwise the merchant should use the guidance above and independent hands-on testing. The label is not a guarantee of detection, a fix, WCAG conformance, or legal compliance.
Primary source: W3C — WCAG 2.2 Understanding 3.3.8