Uploaded image for project: 'mod-password-validator'
  1. mod-password-validator
  2. MODPWD-51

Implement a bad password list(s)

    XMLWordPrintable

Details

    • eHoldings Sprint 98, eHoldings Sprint 101, eHoldings Sprint 102, eHoldings Sprint 103
    • 5
    • Spitfire
    • Backend analysis to identify options. In addition to implementation.

    Description

      As a system administrator,
      I want to validate passwords created/reset/changed
      So that I minimize any efforts to illegal access and attack/harm Folio

      Requirement

      Acceptance Criteria

      Given I need to set/change/reset my password
      When I enter a password that is on the bad password/specified dictionary list(s)
      Then display a message that the password is invalid AND do not allow the password to be saved

      Update: A spike (MODLOGIN-35) was created to find the approach for this functionality. It was completed, and the result was that the online service https://haveibeenpwned.com/Passwords could be used to obtain the list of the bad passwords.

      TestRail: Results

        Attachments

          Issue Links

            Activity

              People

                dmtkachenko Dmytro Tkachenko
                kgambrell Khalilah Gambrell
                Votes:
                0 Vote for this issue
                Watchers:
                8 Start watching this issue

                Dates

                  Created:
                  Updated:
                  Resolved:

                  TestRail: Runs

                    TestRail: Cases