Accessibility rule handbook metadata

Rule
DET.A11Y.GENERIC.ACCESSIBLE_AUTHENTICATION · lane deterministic · scope generic
Page status
current
page_version
083cce5ccdba8ea3f398ea6638a8d0cf66d9afcd71409de3bca009ea3734ab43
generated_at
2026-05-28T05:09:12.000Z
registry_fingerprint
b3797010c3ca988bb0d21d5e85d4efece0b9e83f311c2d4981ebbf402df7a7c2

Related WCAG success criteria

Indicative mapping for compliance reporting — not a conformance claim. Criteria: 3.3.8, 3.3.9

How this rule is checked

Deterministic lane — scope generic. Detected by det-a11y-generic-*.check.js or the axe lane for WCAG-tagged violations.

  • Harness: auditor-tests/invoke-a11y-ruleset-harness.sh on the Before fixture.
  • Audit: analyze-website-a11y.mjs --only-deterministic-rule-ids DET.A11Y.GENERIC.ACCESSIBLE_AUTHENTICATION

Module: docs/design/a11y-audit/deterministic-a11y-rules.md#det-a11y-generic-accessible-authentication. See Before / After below.

Purpose

Deterministic accessibility check (generic scope).

Passing signals

  • DOM and/or repo signals satisfy the rule implementation in tools/website-a11y-auditor.
  • For axe-backed WCAG criteria, use --lanes axe,det with an appropriate --standard preset.

Failing signals

  • Auditor emits a finding with ruleId DET.A11Y.GENERIC.ACCESSIBLE_AUTHENTICATION on the crawled URL.
  • Harness: auditor-tests/invoke-a11y-ruleset-harness.sh DET.A11Y.GENERIC.ACCESSIBLE_AUTHENTICATION expects ≥1 finding on the Before fixture.

Before example

Before (failing example)

Sign in

Log in with your password to access your account.

After example

After (passing example)

Sign in

Log in with your password to access your account.

Paste-friendly sign-in: use a one-time code from email.

Evidence and remediation

  1. Reproduce with analyze-website-a11y.mjs --only-deterministic-rule-ids DET.A11Y.GENERIC.ACCESSIBLE_AUTHENTICATION when lane is deterministic.
  2. Apply the After markup pattern (or fix generator source for KS rules).
  3. Re-run harness or audit until the rule is clean on the target URL.