Download the PHP package crumbls/common-passwords without Composer
On this page you can find all versions of the php package crumbls/common-passwords. It is possible to download/install these versions without Composer. Possible dependencies are resolved automatically.
Download crumbls/common-passwords
More information about crumbls/common-passwords
Files in crumbls/common-passwords
Package common-passwords
Short Description A laravel validation rule to exclude not allow the most common 10,000 passwords and any that you add in.
License
Informations about the package common-passwords
common-passwords
A simple package to validate against common passwords and help keep your application secure.
- php artisan common-passwords:install
- Add the \Crumbls\CommonPasswords\Rules\NotCommonPassword() rule to your password field.
- Best practice says that the best place to do this is to put it into your registration and password recovery validators.
- You can add any extra passwords using the \Crumbls\CommonPasswords\Models\Password model. It only has one field: password
Attached is a simple example that can be ran from anywhere. It will throw a validation exception because we are verifying the password "password" which is a commonly used password.
Since authentication and registration are commonly reinvented based on the application, this is an example of how you could do it in a very basic RegistrationController out of Laravel 8.x. This would overwrite your validator method.
I've had a people ask if you can use this to directly check if a user's password is on this list. It's a horrible idea because of the resources it consumes and this is just brute force testing. That is why you should verify it when you are setting the password. But, if you need to for some reason, here is a simple sample on how to do it.
The documentation is sparse. If you have any questions, feel free to ask here or on twitter @chasecmiller Remember that this is only designed to be a validation rule.