Hacktoberfest 2026:维护者为十月标记出来的 issue,仍然开放、适合新手。 浏览 Hacktoberfest issue

Password/Security overview

未关闭
#89 0 条评论 0 个 reaction 已指派 0 人 在 GitHub 查看

维护者通常 1 天内回复

还没有人认领这个 Issue。

评估

难度
5/5
预计耗时
一周以上
新手友好度
28/100
Issue 类型
功能
描述清晰度
需要澄清
活跃度
活跃
技术栈
android, kotlin

调研方向

从 feature:item:create 中的 LoginRepository.observePasswordScores()、FilterUseCase 和 PasswordGenerator 开始;feature:autofill 展示了概览可能如何依赖该模块。检查 HIBP Pwned Passwords Range API 的要求,包括 k-匿名性和 Add-Padding 处理。直到结果存储和入口点问题得到解决后,这项工作才算完全定义;然后需要覆盖所列出的所有概览、重新生成和泄露检查行为。

由索引模型根据 Issue 内容生成。

描述

A screen that gives an overview of how healthy the user's passwords are, and a quick way to fix weak ones.

Strength distribution

  • Chart showing how many logins fall into each score (Ridiculous, Weak, Moderate, Strong, Excellent)
  • Tapping a category opens the item list with that score filter applied
  • Logins without a password (PasswordScore.None) are not counted as weak

Scores are already stored unencrypted in password.password_score and exposed through LoginRepository.observePasswordScores(), so the chart needs no decryption. The list screen already filters by score (FilterUseCase), so the tap-through can reuse it instead of building a second list.

Scores are calculated when an item is saved (migrated v1 items keep their v1 score), so the chart is only as current as each item's last save.

Regenerate a weak password

The new password must never replace the working one before the user has actually changed it on the website. Otherwise a rejected or abandoned change locks them out.

  • Generate a new password and copy it. The old password stays saved
  • Open the service's website, if the login has one
  • Save the new password only after the user confirms the change worked
  • Quick options for length and symbols, since many sites reject some characters

PasswordGenerator lives in feature:item:create. The overview can depend on that module the way feature:autofill already does.

Breached passwords

Check passwords against the HIBP Pwned Passwords range API. It is free: no API key, no subscription, no attribution required (only HIBP's email and domain search APIs are paid). It uses k-anonymity, so only the first 5 characters of the password's SHA-1 hash ever leave the device.

  • Opt-in, off by default. Nothing is sent until the user enables it
  • Show breached logins as their own category, with a tap-through to the affected items
  • Breached logins can use the regenerate flow above
  • Send the Add-Padding: true header and discard padded rows (count 0)
  • Handle offline and failed requests without marking anything as safe

Passwords with http websites

  • Show passwords that have http-websites applied
  • Show the http protocol
  • Fix button should offer a way to solve this issue. Maybe suggest the https version, or drop the domain??

Health List

  • Sort by severity and within the group by alphanummerics
Open question: storing results

Re-check everything each time the screen opens, or persist a per-item result? A persisted flag would be readable without unlocking (like password_score), so it should either be encrypted or accepted as leaked metadata deliberately.

Open question: entry point

  • A navigation bar tab (next to Home, Connectivity, Settings), or
  • A summary card on Home ("4 weak passwords, Review") that opens the full screen

Out of scope (follow-up)

  • Reused passwords. Finding these means comparing plaintext, so either decrypt all passwords while unlocked or store a hash keyed from the ARK (never a plain hash). This is security-sensitive and needs its own design.
主要语言
Kotlin
星标
56
派生
11
平均合并
2 小时 57 分钟
30 天内合并 PR
14

环境准备

这个项目没有提供开发容器、Dockerfile 或贡献指南,环境需要你自己搭建:先看它的 README,通用步骤见我们的新手贡献指南。

从这里开始

  1. 先读完整个 Issue,再读项目的贡献指南。
  2. 在 Issue 下留言说明你要接手 —— 这能避免两个人做同样的事。
  3. Fork 仓库,在一个分支上完成修改。
  4. 提交 Pull Request,并在描述里引用这个 Issue 编号。

OffRange/KeyGo 的其他 Issue

查看 OffRange/KeyGo 的全部 Issue

相似的 Issue

更多 Kotlin Issue

把新 issue 发到你的邮箱

精选适合新手参与的 GitHub issue 摘要。