nodeSolidServer / nodeSolidServer/node-solid-server

Lookup in Have I Been Pwned? database

未關閉
#904 2 則留言 1 個 reaction 已指派 0 人 在 GitHub 檢視

還沒有人認領這個 Issue。

priority-low
主要語言
JavaScript
星號
1.8k
分支
308
PR 合併指標
30 天內沒有已合併 PR

描述

This came up in https://github.com/solid/node-solid-server/pull/893#discussion_r230898095

Basically, the check in /lib/requests/create-account-request.js#L134 could be extended by looking the email up in Troy Hunt's database. There are packages to do this.

Some measures were already taken in https://github.com/solid/node-solid-server/pull/859 it seems.

If you would want to go fancy, you could look at WebAuthn API :-D

貢獻指南

開啟貢獻指南

從這裡開始

  1. 先讀完整個 Issue,再讀專案的貢獻指南。
  2. 在 Issue 下留言說明你要接手 —— 這能避免兩個人做同樣的事。
  3. Fork 儲存庫,在一個分支上完成修改。
  4. 送出 Pull Request,並在描述裡引用這個 Issue 編號。

研究方向

從 lib/requests/create-account-request.js 第 134 行附近開始,接著閱讀 pull request 893 中的討論以及 pull request 859 中的措施。檢視可用於 Have I Been Pwned 查詢的 npm 套件,並確定比對到外洩事件後帳戶建立應採取的行為。完成的標準是將已達成共識的電子郵件查詢整合到這項檢查中。

由索引模型根據 Issue 內容生成。

評估

技術堆疊
javascript, node.js
領域
backend, security
Issue 類型
功能
難度
4/5
預估耗時
3-5 天
活躍度
停滯
描述清晰度
基本清楚
新手友好度
35/100

把新 issue 寄到你的電子郵件信箱

精選適合新手參與的 GitHub issue 摘要。