django-hibp
This package provides a password validator for Django that validates passwords against HIBP.
django-hibp has no dependencies other than Django and the Python standard library. All code is included in django_hibp.py and can be examined by the user. If anything is unclear, feel free to create an issue and I'll try to explain.
Installation
django-hibp is available on PyPi:
pip install django-hibp
Usage
Add HIBPPasswordValidator to your AUTH_PASSWORD_VALIDATORS settings:
AUTH_PASSWORD_VALIDATORS = [
...
{
'NAME': 'django_hibp.HIBPPasswordValidator',
'OPTIONS': {
'fail_on_error': False,
}
},
]
Since this plugin relies on an external API, this introduces a new point of failure. If the Pwned Passwords API is inaccessible, the check will fail. To avoid breaking your application in this case, set fail_on_error to False.
Privacy
Because of the way the HIBP API works, your password is not exposed during validation. Rather than reiterate everything, I will refer you to the original API documentation, but feel free to create an issue if anything is unclear or bothers you.
Metadata
Release files for django-hibp 1.0
For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.
Built distribution (wheel)
| File | Interpreter | ABI | Platform | Reset |
|---|---|---|---|---|
| django_hibp-1.0-py3-none-any.whl | Python 3 | none | any | Details |
Release files / django_hibp-1.0-py3-none-any.whl
| Download URL | django_hibp-1.0-py3-none-any.whl |
|---|---|
| Size | 3.5 kB |
| Tags | Python 3 |
|
SHA-256 checksum How to use checksums |
f4426840fa243921b75cde2d54a9297bff59fa41022c469a9ac4f791169aba5a
|
|
BLAKE2b-256 checksum How to use checksums |
9b6ab62623c631c73152701916cf266bfcfabacd3a6a7e69fa3bf5ba9ad5639e
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
No |
| Uploaded via |
twine/4.0.2 CPython/3.8.2
|