Skip to main content

Django app for forcing password rotation

Project description

Django password rotation app

This app provides configurable rotation of passwords.

Features

  • Configurable password duration and warning duration
  • Visual warning to user using Django messages
  • Prevents user from accessing any page in after expiration unless the password is changed
  • Forces the new password to be different from previously used passwords
  • Prevents similar passwords (ex: "password1", "password2", ...)

Requirements

This Django app requires Python >= 3.8 and has been tested with Django 4.2, 5.1 and 5.2.

Installation

  1. pip install django-password-rotate.
  2. Add password_rotate to INSTALLED_APPS.
  3. Add 'password_rotate.middleware.PasswordRotateMiddleware' to MIDDLEWARE. It should be listed after authentication and session middlewares.
  4. Add password_rotate.validators.NotPreviousPasswordValidator to AUTH_PASSWORD_VALIDATORS:
AUTH_PASSWORD_VALIDATORS = [
...
{
    "NAME": "password_rotate.validators.NotPreviousPasswordValidator",
},
]
  1. Add the pattern in the urls of your project:
urlpatterns = [
    ...
    path("password_rotate/", include("password_rotate.urls")),
]
  1. Configure the app in your settings:
    # rotate passwords after 90 days
    PASSWORD_ROTATE_SECONDS = 90 * 24 * 60 * 60
    # start warning 10 days before expiration
    PASSWORD_ROTATE_WARN_SECONDS = 10 * 24 * 60 * 60
    # keep at most the 3 previous (encrypted) passwords
    PASSWORD_ROTATE_HISTORY_COUNT = 3
    # when changing the password, allow only a new password with similarity ratio greater than 50
    PASSWORD_ROTATE_MAX_SIMILARITY_RATIO = 50
    
  2. Run python manage.py migrate to create the required database tables.

If you want to exclude superusers from the password expiration, set this flag:

PASSWORD_ROTATE_EXCLUDE_SUPERUSERS = True

Acknowledgements

This app is a direct modification of:

Project details


Download files

Download the file for your platform. If you're not sure which to choose, learn more about installing packages.

Source Distribution

django_password_rotate-1.0.1.tar.gz (11.8 kB view details)

Uploaded Source

Built Distribution

If you're not sure about the file name format, learn more about wheel file names.

django_password_rotate-1.0.1-py3-none-any.whl (16.0 kB view details)

Uploaded Python 3

File details

Details for the file django_password_rotate-1.0.1.tar.gz.

File metadata

File hashes

Hashes for django_password_rotate-1.0.1.tar.gz
Algorithm Hash digest
SHA256 8adfb08272f422c0c0ef65cf102a53edeaed4154838bf2236221449102e27631
MD5 c7eec861d44e801ed7830b500764238d
BLAKE2b-256 4ab33c35b86007a61745624eefe27e086b0f274ee2abd8db2b3d11a5a48f59c5

See more details on using hashes here.

File details

Details for the file django_password_rotate-1.0.1-py3-none-any.whl.

File metadata

File hashes

Hashes for django_password_rotate-1.0.1-py3-none-any.whl
Algorithm Hash digest
SHA256 4b0238a80bec64d533837aa748e7ea84ea098d7b27c75bf4bb4e39db7c975230
MD5 7694836c7de1f9da357d92e3ae4bfe81
BLAKE2b-256 123cf566c6241fb9428e95b15a69cf96053f325884047f90f7ab54e3cc18be48

See more details on using hashes here.

Supported by

AWS Cloud computing and Security Sponsor Datadog Monitoring Depot Continuous Integration Fastly CDN Google Download Analytics Pingdom Monitoring Sentry Error logging StatusPage Status page