Password/Security overview
维护者通常 1 天内回复
还没有人认领这个 Issue。
评估
- 难度
- 5/5
- 预计耗时
- 一周以上
- 新手友好度
- 28/100
- Issue 类型
- 功能
- 描述清晰度
- 需要澄清
- 活跃度
- 活跃
- 领域
- mobile-dev, security
调研方向
从 feature:item:create 中的 LoginRepository.observePasswordScores()、FilterUseCase 和 PasswordGenerator 开始;feature:autofill 展示了概览可能如何依赖该模块。检查 HIBP Pwned Passwords Range API 的要求,包括 k-匿名性和 Add-Padding 处理。直到结果存储和入口点问题得到解决后,这项工作才算完全定义;然后需要覆盖所列出的所有概览、重新生成和泄露检查行为。
由索引模型根据 Issue 内容生成。
描述
A screen that gives an overview of how healthy the user's passwords are, and a quick way to fix weak ones.
Strength distribution
- Chart showing how many logins fall into each score (Ridiculous, Weak, Moderate, Strong, Excellent)
- Tapping a category opens the item list with that score filter applied
- Logins without a password (
PasswordScore.None) are not counted as weak
Scores are already stored unencrypted in password.password_score and exposed through LoginRepository.observePasswordScores(), so the chart needs no decryption. The list screen already filters by score (FilterUseCase), so the tap-through can reuse it instead of building a second list.
Scores are calculated when an item is saved (migrated v1 items keep their v1 score), so the chart is only as current as each item's last save.
Regenerate a weak password
The new password must never replace the working one before the user has actually changed it on the website. Otherwise a rejected or abandoned change locks them out.
- Generate a new password and copy it. The old password stays saved
- Open the service's website, if the login has one
- Save the new password only after the user confirms the change worked
- Quick options for length and symbols, since many sites reject some characters
PasswordGenerator lives in feature:item:create. The overview can depend on that module the way feature:autofill already does.
Breached passwords
Check passwords against the HIBP Pwned Passwords range API. It is free: no API key, no subscription, no attribution required (only HIBP's email and domain search APIs are paid). It uses k-anonymity, so only the first 5 characters of the password's SHA-1 hash ever leave the device.
- Opt-in, off by default. Nothing is sent until the user enables it
- Show breached logins as their own category, with a tap-through to the affected items
- Breached logins can use the regenerate flow above
- Send the
Add-Padding: trueheader and discard padded rows (count0) - Handle offline and failed requests without marking anything as safe
Passwords with http websites
- Show passwords that have http-websites applied
- Show the http protocol
- Fix button should offer a way to solve this issue. Maybe suggest the https version, or drop the domain??
Health List
- Sort by severity and within the group by alphanummerics
Open question: storing results
Re-check everything each time the screen opens, or persist a per-item result? A persisted flag would be readable without unlocking (like password_score), so it should either be encrypted or accepted as leaked metadata deliberately.
Open question: entry point
- A navigation bar tab (next to Home, Connectivity, Settings), or
- A summary card on Home ("4 weak passwords, Review") that opens the full screen
Out of scope (follow-up)
- Reused passwords. Finding these means comparing plaintext, so either decrypt all passwords while unlocked or store a hash keyed from the ARK (never a plain hash). This is security-sensitive and needs its own design.
- 主要语言
- Kotlin
- 星标
- 56
- 派生
- 11
- 平均合并
- 2 小时 57 分钟
- 30 天内合并 PR
- 14
环境准备
这个项目没有提供开发容器、Dockerfile 或贡献指南,环境需要你自己搭建:先看它的 README,通用步骤见我们的新手贡献指南。
从这里开始
- 先读完整个 Issue,再读项目的贡献指南。
- 在 Issue 下留言说明你要接手 —— 这能避免两个人做同样的事。
- Fork 仓库,在一个分支上完成修改。
- 提交 Pull Request,并在描述里引用这个 Issue 编号。
OffRange/KeyGo 的其他 Issue
-
bug
难度 2/5 1-3 小时 新手友好度 66/100
维护者通常 1 天内回复
-
enhancement
难度 3/5 1-2 天 新手友好度 65/100
维护者通常 1 天内回复
-
dependencies enhancement
难度 4/5 3-5 天 新手友好度 52/100
维护者通常 1 天内回复
-
Version 2.1.0未关闭
难度 5/5 一周以上 新手友好度 10/100
维护者通常 1 天内回复
-
create an extension for the browser可能重新可做 @OffRange 于 872 天前认领,目前没有进行中的 PR。 未关闭enhancement
维护者通常 1 天内回复
相似的 Issue
-
bug
难度 2/5 1-3 小时 新手友好度 84/100
-
enhancement
难度 2/5 1-3 小时 新手友好度 78/100
维护者通常 1 天内回复
-
难度 2/5 1-3 小时 新手友好度 72/100
SimonHalvdansson/Harmonic-HN#363 ·
-
难度 2/5 1-3 小时 新手友好度 88/100
维护者通常 1 天内回复
-
难度 2/5 1-3 小时 新手友好度 90/100
Automattic/pocket-casts-android#6095 ·
维护者通常 1 天内回复