I’d be happy with just:
- an “alphabet”, “minlength” and “maxlength” attributes on password fields so password managers generate perfect passwords every time
- a well-known URI for password managers to do zero-touch password rotation.
- actual elements for login components to close the confused deputy attack for password managers.
All these things would be much easier changes for crufty old sites to make, which would aid adoption.