[Xon] Password Tools

[Xon] Password Tools 3.11.1

No permission to download
thanks to dear member @jessy updated [Xon] Password Tools with a new update entry:

changelog

  • Fix "Minimum time between triggering compromised password alerts on login" operating in seconds instead of hours
  • Fix cases where email 2fa would not be forced enabled on the first login request after a password is discovered as compromised
  • Rename various options to be better searchable
  • Adjust various option defaults to be more robust.
    • 'Minimum password length' from 8 => 10 characters
    • 'Minimum password strength' from 'very weak' to 'weak'
    • 'Pwned password...

Read the rest of this update entry...
 
thanks to dear member @jessy updated [Xon] Password Tools with a new update entry:

changelog

  • Fix changing user entity while a write is pending in some cases
  • Add "Use rejected password fragments in password meter" option (default disabled).
    Take rejected password fragments into consideration when showing the password strength meter to the user.
    Security note: this makes the full list of rejected password fragments visible to end users; ensure that there aren't any sensitive password fragments before enabling.

Read the rest of this update entry...
 
thanks to dear member @jessy updated [Xon] Password Tools with a new update entry:

changelog

php 8.4+ compatibility fixes
Rename option "Password check types" to "New password validation rules"
Add "On login; consider known-bad passwords as compromised" option (default false)
Add new password validation rule "Prevent passwords which contain the user's email or username, and the site's domain/name." (default false)

Read the rest of this update entry...
 
Top