I used the password reset to change it. This time I used a pretty short password I could type (to rule out a weird copy-paste bug or something). Logged in, went to the change password option and THAT page informed me there was a character limit.
They reveal that the back-end service probably doesn't hash the passwords, which is a good time to GTFO.
This way you can have strong input validation server side but also allow almost arbitrary inputs client side.
PS: you likely could also salt the client side hashing and use bcrypt, but bcrypt has a quite short maximum length and I am not sure if it would provide significantly better security here.
This i what happens with the 4 digits of a CC PIN and the 3 attempts before the card switches into PUK mode.
It's like they're deliberately trying to reduce the pool of valid inputs.
So I reduce the length, significantly, sometimes to 8 characters.
The people who make rules in security in some areas are complete idiots.
Eventually I convinced leadership to invest in basic security after conservative but still embarrassingly high 6-to-7-figure estimates of annual loss expectancy that only took a measly 5 figures a year to eliminate 75% of the risk, but the company only went around to it a long while after I left the place.
I don't know what makes a manager turn off snooze on open PRs for fixing blatant holes.
But if you've got that skill, it can take you far!
If I pasted my password it failed, but if I auto-filled from bitwarden it succeeded. Took me weeks to figure out why...
It took me several password reset attempts to realise what was going on, as my literally just set and password manager-saved password didn't work.
I think in BA's case the password input also had a character limit on it, which is ultimately how I realised what was happening, even though there was no info anywhere that such a limit existed.