Skip to content
Snippets Groups Projects
Unverified Commit 8887b936 authored by Fredrik Jonsson's avatar Fredrik Jonsson Committed by GitHub
Browse files

Merge pull request #594 from OpenTechFund/feature/572-use-pwnedpasswords-check

Make use of pwnedpasswords check and set min length to 12.
parents f2f41a2f 44ba0fd5
No related branches found
No related tags found
No related merge requests found
...@@ -31,7 +31,7 @@ ...@@ -31,7 +31,7 @@
{{ field }} {{ field }}
{% if field.errors %}<h6 class="form__error-text">{{ field.errors.as_text }}</h6>{% endif %} {% if field.errors %}<h6 class="form__error-text">{{ field.errors.as_text|linebreaksbr }}</h6>{% endif %}
<label for="{{ field.id_for_label }}"></label> <label for="{{ field.id_for_label }}"></label>
{% if widget_type == 'date_input' or widget_type == 'date_time_input' %} {% if widget_type == 'date_input' or widget_type == 'date_time_input' %}
</div> </div>
......
...@@ -114,6 +114,7 @@ INSTALLED_APPS = [ ...@@ -114,6 +114,7 @@ INSTALLED_APPS = [
'addressfield', 'addressfield',
'django_bleach', 'django_bleach',
'django_fsm', 'django_fsm',
'django_pwned_passwords',
'hijack', 'hijack',
'compat', 'compat',
...@@ -228,17 +229,17 @@ WAGTAILSEARCH_BACKENDS = { ...@@ -228,17 +229,17 @@ WAGTAILSEARCH_BACKENDS = {
# https://docs.djangoproject.com/en/stable/ref/settings/#auth-password-validators # https://docs.djangoproject.com/en/stable/ref/settings/#auth-password-validators
AUTH_PASSWORD_VALIDATORS = [ AUTH_PASSWORD_VALIDATORS = [
{
'NAME': 'django.contrib.auth.password_validation.UserAttributeSimilarityValidator',
},
{ {
'NAME': 'django.contrib.auth.password_validation.MinimumLengthValidator', 'NAME': 'django.contrib.auth.password_validation.MinimumLengthValidator',
'OPTIONS': {
'min_length': 12,
}
}, },
{ {
'NAME': 'django.contrib.auth.password_validation.CommonPasswordValidator', 'NAME': 'django.contrib.auth.password_validation.UserAttributeSimilarityValidator',
}, },
{ {
'NAME': 'django.contrib.auth.password_validation.NumericPasswordValidator', 'NAME': 'django_pwned_passwords.password_validation.PWNEDPasswordValidator',
}, },
] ]
......
...@@ -31,6 +31,7 @@ django_select2==6.0.1 ...@@ -31,6 +31,7 @@ django_select2==6.0.1
dj-database-url==0.5.0 dj-database-url==0.5.0
django-basic-auth-ip-whitelist==0.2.1 django-basic-auth-ip-whitelist==0.2.1
django-heroku==0.3.1 django-heroku==0.3.1
django-pwned-passwords==2.0.0
django-redis==4.9.0 django-redis==4.9.0
django-referrer-policy==1.0 django-referrer-policy==1.0
whitenoise==4.0 whitenoise==4.0
......
0% Loading or .
You are about to add 0 people to the discussion. Proceed with caution.
Finish editing this message first!
Please register or to comment