django-pwned-passwords is a Django password validator that checks Troy Hunt’s PWNED Passwords API to see if a password has been involved in a major security breach before.
Note: This app currently sends a portion of a user’s hashed password to a third party. Before using this application, you should understand how that impacts you.
Documentation
The full documentation is at https://django-pwned-passwords.readthedocs.io.
Requirements
Django [1.9, 2.1]
Python 2.7, [3.5, 3.6, 3.7]
Quickstart
Install django-pwned-passwords:
pip install django-pwned-passwords
Add it to your INSTALLED_APPS:
INSTALLED_APPS = (
...
'django_pwned_passwords',
...
)
Add django-pwned-passwords’s PWNEDPasswordValidator:
AUTH_PASSWORD_VALIDATORS = [
...
{
'NAME': 'django_pwned_passwords.password_validation.PWNEDPasswordValidator'
}
]
Features
This password validator returns a ValidationError if the PWNED Passwords API
detects the password in its data set. Note that the API is heavily rate-limited,
so there is a timeout (PWNED_VALIDATOR_TIMEOUT).
If PWNED_VALIDATOR_FAIL_SAFE is True, anything besides an API-identified bad password
will pass, including a timeout. If PWNED_VALIDATOR_FAIL_SAFE is False, anything
besides a good password will fail and raise a ValidationError.
Settings
Setting |
Description |
Default |
|
The timeout in seconds. The validator will not wait longer than this for a response from the API. |
|
|
If the API fails to get a valid response, should we fail safe and allow the password through? |
|
|
The URL for the API in a string format. |
|
|
The error message for an invalid password. |
|
|
The error message when the API fails. Note: this will only display if |
|
|
The help text for this password validator. |
|
|
The minimum number of breaches needed to raise an error |
|
Rate Limiting
Historically, requests to the API were rate limited. However, with the new k-anonymity model-based API, there are no such rate limits.
Running Tests
source <YOURVIRTUALENV>/bin/activate (myenv) $ pip install tox (myenv) $ tox
Credits
Tools used in rendering this package:
History
See Github Releases
Metadata
Release files for django-pwned-passwords 4.1.0
For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.
Source distribution (sdist)
| File | Size | Uploaded | |
|---|---|---|---|
| django-pwned-passwords-4.1.0.tar.gz | 7.0 kB | Details |
Built distribution (wheel)
| File | Interpreter | ABI | Platform | Reset |
|---|---|---|---|---|
| django_pwned_passwords-4.1.0-py2.py3-none-any.whl | Python 3, Python 2 | none | any | Details |
Total release size: 14.6 kB
Release files / django-pwned-passwords-4.1.0.tar.gz
| Download URL | django-pwned-passwords-4.1.0.tar.gz |
|---|---|
| Size | 7.0 kB |
| Tags | Source |
|
SHA-256 checksum How to use checksums |
a75aa7b584dcfd7874c49deb2fd303cc2356f7bf39cf63cbb22b575b242c7a34
|
|
BLAKE2b-256 checksum How to use checksums |
f952035938b4c793aded4dfcee816fb35b8d332d7efb5a593b5d98493a5ba5dd
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
No |
| Uploaded via |
Python-urllib/3.6
|
Release files / django_pwned_passwords-4.1.0-py2.py3-none-any.whl
| Download URL | django_pwned_passwords-4.1.0-py2.py3-none-any.whl |
|---|---|
| Size | 7.6 kB |
| Tags | Python 2 Python 3 |
|
SHA-256 checksum How to use checksums |
62f198ced2570ea4a21bb595ac6e46b8192b97a2064fbed95c9d550adf16dbaa
|
|
BLAKE2b-256 checksum How to use checksums |
0ac965cb61f64d822a638b0831bef4c20f411f3dce4864034e6dbddcce6c5731
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
No |
| Uploaded via |
Python-urllib/3.6
|