Skip to main content

Django app for forcing password rotation

Project description

Django password rotation app

This app provides configurable rotation of passwords.

Features

  • Configurable password duration and warning duration
  • Visual warning to user using Django messages
  • Prevents user from accessing any page in after expiration unless the password is changed
  • Forces the new password to be different from previously used passwords
  • Prevents similar passwords (ex: "password1", "password2", ...)

Requirements

This Django app requires Python >= 3.8 and has been tested with Django 4.2, 5.1 and 5.2.

Installation

  1. pip install django-password-rotate.
  2. Add password_rotate to INSTALLED_APPS.
  3. Add 'password_rotate.middleware.PasswordRotateMiddleware' to MIDDLEWARE. It should be listed after authentication and session middlewares.
  4. Add password_rotate.validators.NotPreviousPasswordValidator to AUTH_PASSWORD_VALIDATORS:
AUTH_PASSWORD_VALIDATORS = [
...
{
    "NAME": "password_rotate.validators.NotPreviousPasswordValidator",
},
]
  1. Add the pattern in the urls of your project:
urlpatterns = [
    ...
    path("password_rotate/", include("password_rotate.urls")),
]
  1. Configure the app in your settings:
    # rotate passwords after 90 days
    PASSWORD_ROTATE_SECONDS = 90 * 24 * 60 * 60
    # start warning 10 days before expiration
    PASSWORD_ROTATE_WARN_SECONDS = 10 * 24 * 60 * 60
    # keep at most the 3 previous (encrypted) passwords
    PASSWORD_ROTATE_HISTORY_COUNT = 3
    # when changing the password, allow only a new password with similarity ratio greater than 50
    PASSWORD_ROTATE_MAX_SIMILARITY_RATIO = 50
    
  2. Run python manage.py migrate to create the required database tables.

If you want to exclude superusers from the password expiration, set this flag:

PASSWORD_ROTATE_EXCLUDE_SUPERUSERS = True

Acknowledgements

This app is a direct modification of:

Project details


Download files

Download the file for your platform. If you're not sure which to choose, learn more about installing packages.

Source Distribution

django_password_rotate-1.0.2.tar.gz (12.4 kB view details)

Uploaded Source

Built Distribution

If you're not sure about the file name format, learn more about wheel file names.

django_password_rotate-1.0.2-py3-none-any.whl (16.9 kB view details)

Uploaded Python 3

File details

Details for the file django_password_rotate-1.0.2.tar.gz.

File metadata

File hashes

Hashes for django_password_rotate-1.0.2.tar.gz
Algorithm Hash digest
SHA256 14143631fc7b0f17e2573a24bd677ac0ead297f133584023829d0fda728384ad
MD5 86b7b113fc815c9a98a6feb5411075cc
BLAKE2b-256 b1ff2e00e926e17467d015bbad654fd524739d1c1b8e718fb959f5464115c257

See more details on using hashes here.

File details

Details for the file django_password_rotate-1.0.2-py3-none-any.whl.

File metadata

File hashes

Hashes for django_password_rotate-1.0.2-py3-none-any.whl
Algorithm Hash digest
SHA256 0c0f8a250bcb77f53a7f502298e918ce8a092af3fc7d62c1a1f28db40f4687b2
MD5 9d48b1db72a9f8df816f02b73bb6072f
BLAKE2b-256 323f9ffaceb601c2ed8493123bb9b987ddbc17a60c4f55f31551ff146cdd0b4c

See more details on using hashes here.

Supported by

AWS Cloud computing and Security Sponsor Datadog Monitoring Depot Continuous Integration Fastly CDN Google Download Analytics Pingdom Monitoring Sentry Error logging StatusPage Status page