icingaweb2 icon indicating copy to clipboard operation
icingaweb2 copied to clipboard

Implement password policy with hook

Open JolienTrog opened this issue 4 months ago • 3 comments

Ref #4401

JolienTrog avatar Aug 26 '25 09:08 JolienTrog

Also, please rebase.

lippserd avatar Oct 11 '25 11:10 lippserd

💡

@lippserd What do you think about this:

ChangePasswordForm already has the old and new password. So PasswordPolicy can take both.

It would cost us nothing, but admins could implement #5417 by themselves. They could also use e.g Levenshtein distance and/or A.I to prevent the "smartest" users from using passwords similar to their current ones.

Al2Klimov avatar Dec 02 '25 15:12 Al2Klimov

💡

@lippserd What do you think about this:

ChangePasswordForm already has the old and new password. So PasswordPolicy can take both.

It would cost us nothing, but admins could implement #5417 by themselves. They could also use e.g Levenshtein distance and/or A.I to prevent the "smartest" users from using passwords similar to their current ones.

That's a good idea! @JolienTrog Could you please adjust the implementation so that the validation function accepts both $newPassword and $oldPassword, where the latter may be null?

lippserd avatar Dec 03 '25 08:12 lippserd