spring-projects / spring-projects/spring-security
Simplify Custom Handling for Compromised Passwords
Open
@jzheaux is already working on this.
Since Apr 8, 2025.
in: web
type: enhancement
- Dominant language
- Java
- Stars
- 9.6k
- Forks
- 6.3k
- Avg merge
- 2d 11h
- Merged PRs (30d)
- 52
Description
Right now it is simple to prevent a user from authenticating when they have a compromised password. However, we should support more flows:
- Allow the user to authenticate, but force the user to change their password before doing anything else
- Allow the user to authenticate, but post a warning that the password was compromised
- Checking when a password is changed
Related gh-15745
Contributor guide
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
Assessment
This issue has not been assessed yet.