Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Forbid username, domain, themed name as password #96

Open
Admin-Viatos opened this issue Jan 30, 2020 · 3 comments
Open

Forbid username, domain, themed name as password #96

Admin-Viatos opened this issue Jan 30, 2020 · 3 comments

Comments

@Admin-Viatos
Copy link

Hello everyone,

yesterday I discovered a strange thing: it’s possible to use the Username as password (testet in NC17 and NC18). App "password policy" is active.

If your Username rules the password policy you can set the Username as password

Should that be so ???

@kesselb
Copy link
Contributor

kesselb commented Jan 30, 2020

cc @nextcloud/security

Nextcloud is also accepting contributions ;) Code for password_policy is here: https://github.com/nextcloud/password_policy

@rullzer
Copy link
Member

rullzer commented Jan 30, 2020

@Admin-Viatos ah you found my secret TODO list.

So yes. Currently this is allowed. But you are right that it probably should not be.
Same goes for the domain, and the themed name of the site etc. All of this should be blocked in my opinion (or at least be configured to be blocked).

As said by @kesselb if you have any php coding skills (or want to learn). See https://github.com/nextcloud/password_policy where we handle this :)

@georgehrke
Copy link
Member

Moving to password_policy repository ...

@georgehrke georgehrke transferred this issue from nextcloud/server Jan 30, 2020
@georgehrke georgehrke changed the title Security-Flaw or Design - Username as Password? Forbid username, domain, themed name as password Jan 30, 2020
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

No branches or pull requests

4 participants