Select a bad password list(s)

Description

As a system administrator,
I want to validate passwords created/reset/changed
So that I minimize any efforts to illegal access and attack/harm Folio

Requirement

  • Select a bad password list to check passwords

  • Select a specified dictionary recommended to check password

  • Development should be flexible enough to support adding/removing more list(s)/dictionary(ies) as needed

Acceptance Criteria

Given I need to set/change/reset my password

When I enter a password that is on the bad password/specified dictionary list(s)
Then display a message that the password is invalid AND do not allow the password to be saved

Environment

None

Potential Workaround

None

Checklist

hide

TestRail: Results

Activity

Show:

Igor GorchakovJuly 26, 2018 at 9:45 AM

My investigation has been done, I'm ready to implement it.

Khalilah GambrellJuly 25, 2018 at 2:51 PM

@kurt, if we selected a list and an approach has been approved then can close this user story. And the implementation piece can be handled with MODLOGIN-34.

Kurt NordstromJuly 25, 2018 at 2:47 PM

Can we perhaps merge this issue with https://folio-org.atlassian.net/browse/MODLOGIN-34?

Igor GorchakovJuly 25, 2018 at 1:56 PM

I would prefer to use back-end implementation because it brings more benefits,
please see the most fresh up-to-date comments in cloned ticket
https://folio-org.atlassian.net/browse/MODLOGIN-34

Kurt NordstromJuly 25, 2018 at 12:28 PM

I think it makes sense to use the haveibeenpwned service as part of the front-end part of the password change interface.

I believe this aligns with conversations that I had with and .

Done

Details

Assignee

Reporter

Priority

Story Points

Sprint

Development Team

Folijet

TestRail: Cases

Open TestRail: Cases

TestRail: Runs

Open TestRail: Runs

Created May 21, 2018 at 11:21 PM
Updated October 2, 2018 at 4:17 PM
Resolved July 26, 2018 at 9:45 AM
TestRail: Cases
TestRail: Runs