spring-projects / spring-projects/spring-security

Include Compromised Password Information in `UserDetails`

Open
#15,745 2 comments 0 reactions 1 assignee View on GitHub

@jgrandja is already working on this.

Since Oct 10, 2024.

in: core type: enhancement
Dominant language
Java
Stars
9.6k
Forks
6.3k
Avg merge
2d 11h
Merged PRs (30d)
52

Description

Currently, there is no easy way to flag a UserDetails object that has its password compromised. There is no first-class property in Spring Security to identify that.

This will entail:

  • Update UserDetails with a default method that shows if the password is compromised
  • Update User and it's builder to have the property
  • Update DaoAuthenticationProvider to ensure to set the property

See this sample https://github.com/spring-projects/spring-security-samples/tree/main/servlet/spring-boot/java/authentication/username-password/compromised-password-checker

Contributor guide

Open the contributing guide

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

Assessment

This issue has not been assessed yet.

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.