Hacktoberfest 2026: le issue che i maintainer hanno segnato per ottobre, aperte e adatte ai principianti. Sfoglia le issue Hacktoberfest

Password/Security overview

Aperta
#89 0 commenti 0 reazioni 0 assegnatari Vedi su GitHub

I maintainer di solito rispondono entro 1 giorno

Nessuno ha ancora preso questa issue.

Valutazione

Difficoltà
5/5
Tempo stimato
Più di una settimana
Idoneità per principianti
28/100
Tipo di issue
Funzionalità
Chiarezza
Da chiarire
Stato di attività
Attiva
Stack tecnologico
android, kotlin

Direzione di ricerca

Inizia con LoginRepository.observePasswordScores(), FilterUseCase e PasswordGenerator in feature:item:create; feature:autofill mostra come la panoramica potrebbe dipendere da quel modulo. Esamina i requisiti della HIBP Pwned Passwords Range API, inclusi la k-anonimizzazione e la gestione di Add-Padding. Il lavoro non sarà completamente definito finché non saranno risolte le questioni relative all'archiviazione del risultato e al punto di ingresso; quindi sarà necessario coprire tutti i comportamenti elencati relativi a panoramica, rigenerazione e controllo delle violazioni.

Scritto dal modello di indicizzazione a partire dal testo della issue.

Descrizione

A screen that gives an overview of how healthy the user's passwords are, and a quick way to fix weak ones.

Strength distribution

  • Chart showing how many logins fall into each score (Ridiculous, Weak, Moderate, Strong, Excellent)
  • Tapping a category opens the item list with that score filter applied
  • Logins without a password (PasswordScore.None) are not counted as weak

Scores are already stored unencrypted in password.password_score and exposed through LoginRepository.observePasswordScores(), so the chart needs no decryption. The list screen already filters by score (FilterUseCase), so the tap-through can reuse it instead of building a second list.

Scores are calculated when an item is saved (migrated v1 items keep their v1 score), so the chart is only as current as each item's last save.

Regenerate a weak password

The new password must never replace the working one before the user has actually changed it on the website. Otherwise a rejected or abandoned change locks them out.

  • Generate a new password and copy it. The old password stays saved
  • Open the service's website, if the login has one
  • Save the new password only after the user confirms the change worked
  • Quick options for length and symbols, since many sites reject some characters

PasswordGenerator lives in feature:item:create. The overview can depend on that module the way feature:autofill already does.

Breached passwords

Check passwords against the HIBP Pwned Passwords range API. It is free: no API key, no subscription, no attribution required (only HIBP's email and domain search APIs are paid). It uses k-anonymity, so only the first 5 characters of the password's SHA-1 hash ever leave the device.

  • Opt-in, off by default. Nothing is sent until the user enables it
  • Show breached logins as their own category, with a tap-through to the affected items
  • Breached logins can use the regenerate flow above
  • Send the Add-Padding: true header and discard padded rows (count 0)
  • Handle offline and failed requests without marking anything as safe

Passwords with http websites

  • Show passwords that have http-websites applied
  • Show the http protocol
  • Fix button should offer a way to solve this issue. Maybe suggest the https version, or drop the domain??

Health List

  • Sort by severity and within the group by alphanummerics
Open question: storing results

Re-check everything each time the screen opens, or persist a per-item result? A persisted flag would be readable without unlocking (like password_score), so it should either be encrypted or accepted as leaked metadata deliberately.

Open question: entry point

  • A navigation bar tab (next to Home, Connectivity, Settings), or
  • A summary card on Home ("4 weak passwords, Review") that opens the full screen

Out of scope (follow-up)

  • Reused passwords. Finding these means comparing plaintext, so either decrypt all passwords while unlocked or store a hash keyed from the ARK (never a plain hash). This is security-sensitive and needs its own design.
Lingua principale
Kotlin
Stelle
56
Fork
11
Merge medio
2h 57m
PR unite (30g)
14

Preparare l'ambiente

Questo progetto non fornisce container di sviluppo, Dockerfile né guida per i contributori, quindi l'ambiente è a tuo carico: parti dal suo README e consulta la nostra guida al primo contributo per i passaggi generali.

Come iniziare

  1. Leggi tutta la issue e poi la guida ai contributi del progetto.
  2. Commenta sulla issue per dire che te ne occupi tu — evita che due persone facciano lo stesso lavoro.
  3. Fai un fork del repository e lavora su un branch.
  4. Apri una pull request che faccia riferimento al numero della issue.

Altre issue di OffRange/KeyGo

Tutte le issue di OffRange/KeyGo

Issue simili

Altre issue su Kotlin

Ricevi le nuove issue nella tua casella

Un breve riepilogo di issue GitHub adatte ai principianti.