blueprints: add default Password policy (cherry-pick #11793)#11993
Merged
BeryJu merged 1 commit intoversion-2024.10from Nov 11, 2024
Merged
blueprints: add default Password policy (cherry-pick #11793)#11993BeryJu merged 1 commit intoversion-2024.10from
BeryJu merged 1 commit intoversion-2024.10from
Conversation
* add password policy to default password change flow This change complies with the minimal compositional requirements by NIST SP 800-63 Digital Identity Guidelines. See https://pages.nist.gov/800-63-4/sp800-63b.html#password More work is needed to comply with other parts of the Guidelines, specifically > If the chosen password is found on the blocklist, the CSP or verifier > [...] SHALL provide the reason for rejection. and > Verifiers SHALL offer guidance to the subscriber to assist the user in > choosing a strong password. This is particularly important following > the rejection of a password on the blocklist as it discourages trivial > modification of listed weak passwords. * add docs for default Password policy * remove HIBP from default Password policy * add zxcvbn to default Password policy * add fallback password error message to password policy, fix validation policy Signed-off-by: Jens Langhammer <jens@goauthentik.io> * reword docs Co-authored-by: Tana M Berry <tanamarieberry@yahoo.com> Signed-off-by: Simonyi Gergő <28359278+gergosimonyi@users.noreply.github.com> * add HIBP caveat Co-authored-by: Jens L. <jens@goauthentik.io> Signed-off-by: Simonyi Gergő <28359278+gergosimonyi@users.noreply.github.com> * separate policy into separate blueprint Signed-off-by: Jens Langhammer <jens@goauthentik.io> * use password policy for oobe flow Signed-off-by: Jens Langhammer <jens@goauthentik.io> * kiss Signed-off-by: Jens Langhammer <jens@goauthentik.io> --------- Signed-off-by: Jens Langhammer <jens@goauthentik.io> Signed-off-by: Simonyi Gergő <28359278+gergosimonyi@users.noreply.github.com> Co-authored-by: Jens Langhammer <jens@goauthentik.io> Co-authored-by: Tana M Berry <tanamarieberry@yahoo.com>
✅ Deploy Preview for authentik-docs ready!
To edit notification comments on pull requests, go to your Netlify site configuration. |
Codecov ReportAttention: Patch coverage is
✅ All tests successful. No failed tests found.
Additional details and impacted files@@ Coverage Diff @@
## version-2024.10 #11993 +/- ##
===================================================
- Coverage 92.57% 92.56% -0.02%
===================================================
Files 761 761
Lines 37818 37822 +4
===================================================
- Hits 35011 35009 -2
- Misses 2807 2813 +6
Flags with carried forward coverage won't be shown. Click here to find out more. ☔ View full report in Codecov by Sentry. |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Cherry-picked blueprints: add default Password policy (#11793)
This change complies with the minimal compositional requirements by
NIST SP 800-63 Digital Identity Guidelines. See
https://pages.nist.gov/800-63-4/sp800-63b.html#password
More work is needed to comply with other parts of the Guidelines,
specifically
and
add docs for default Password policy
remove HIBP from default Password policy
add zxcvbn to default Password policy
add fallback password error message to password policy, fix validation policy
Signed-off-by: Jens Langhammer jens@goauthentik.io
Co-authored-by: Tana M Berry tanamarieberry@yahoo.com
Signed-off-by: Simonyi Gergő 28359278+gergosimonyi@users.noreply.github.com
Co-authored-by: Jens L. jens@goauthentik.io
Signed-off-by: Simonyi Gergő 28359278+gergosimonyi@users.noreply.github.com
Signed-off-by: Jens Langhammer jens@goauthentik.io
Signed-off-by: Jens Langhammer jens@goauthentik.io
Signed-off-by: Jens Langhammer jens@goauthentik.io
Signed-off-by: Jens Langhammer jens@goauthentik.io
Signed-off-by: Simonyi Gergő 28359278+gergosimonyi@users.noreply.github.com
Co-authored-by: Jens Langhammer jens@goauthentik.io
Co-authored-by: Tana M Berry tanamarieberry@yahoo.com