Management for Passwords reset and exposed to internet
- Dominant language
- No language data
- Stars
- 39
- Forks
- 1
- PR merge metrics
- No merged PRs in 30d
Description
Sites get hacked. We need to deal with that eventuality. I'm looking to solve two things
a) Admin sets password for user (from commandline), emails to user, user does not change the password. Someone gets access to email, the password is right there and it works. Since CKAN portals would have high visibility, this is an attack vector we'd need to think about. I'd say that the user would need to reset the password at first login.
b) The CKAN database has been exposed and made public. We've protected our passwords now, but I think it'd be useful to have a way for admins to delete everyone's password (and reset key) at one go and force users to click Forget Password to get a new password.
Thoughts about the best way to go about this? I'm going to spend some time working on this. I'm looking for concrete opinions and ideas on how this should proceed.
Contributor guide
No contributing guide indexed for this repository
Research direction
Start by reviewing the two scenarios in the issue: first-login password changes after administrator resets, and a global invalidation of passwords and reset keys after database exposure. The issue names no files, tests, or entry points, so the implementation location and completion criteria still need to be established through project discussion.
Written by the indexing model from the issue text.
Assessment
- Domain
- authentication, security
- Issue type
- Feature
- Difficulty
- 5/5
- Estimated time
- Over a week
- Activity status
- Stale
- Clarity
- Needs clarification
- Newbie friendliness
- 20/100