I just noticed that when resetting a user password via the Octoja interface, no error message appears if the one-time password provided does not comply with the domain's password policies.
From a user-friendliness perspective, it would be helpful if Octoja provided appropriate feedback in this case—for example, a message indicating that the password does not meet the applicable security policies.
Currently, users end up waiting an unnecessarily long time for a response and initially assume that the process is still being processed. 😄