Accessible Authentication, new in WCAG 2.2, requires that a login step not depend purely on a user’s memory, transcription, or puzzle-solving ability unless an alternative is offered, such as allowing password managers and browser autofill to work, supporting copy-paste into password fields, or offering a biometric or email-link option instead of a memorized password.
This directly affects people with cognitive disabilities and memory impairments, but it also benefits everyone: blocking paste into a password field, still common on some login forms, actively works against password manager use for every user, not just those with disabilities.