mirror of
https://github.com/dani-garcia/vaultwarden.git
synced 2026-04-26 17:55:58 +03:00
[PR #1848] [MERGED] Password hint enhancements #3017
Labels
No labels
SSO
Third party
better for forum
bug
bug
documentation
duplicate
enhancement
future Vault
future Vault
future Vault
good first issue
help wanted
low priority
notes
pull-request
question
troubleshooting
wontfix
No milestone
No project
No assignees
1 participant
Notifications
Due date
No due date set.
Dependencies
No dependencies set.
Reference
starred/vaultwarden#3017
Loading…
Add table
Add a link
Reference in a new issue
No description provided.
Delete branch "%!s()"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
📋 Pull Request Information
Original PR: https://github.com/dani-garcia/vaultwarden/pull/1848
Author: @jjlin
Created: 7/10/2021
Status: ✅ Merged
Merged: 7/15/2021
Merged by: @dani-garcia
Base:
main← Head:password-hints📝 Commits (2)
8ee5d51Disableshow_password_hintby default88bea44Prevent user enumeration via password hints📊 Changes
3 files changed (+43 additions, -19 deletions)
View changed files
📝
.env.template(+4 -2)📝
src/api/core/accounts.rs(+35 -14)📝
src/config.rs(+4 -3)📄 Description
Disable
show_password_hintby default.A setting that provides unauthenticated access to potentially sensitive data shouldn't be enabled by default.
Prevent user enumeration via password hints
When
show_password_hintis enabled but mail is not configured, the previous implementation returned a differentiable response for non-existent email addresses.Even if mail is enabled, there is a timing side channel since mail is sent synchronously. Add a randomized sleep to mitigate this somewhat.
🔄 This issue represents a GitHub Pull Request. It cannot be merged through Gitea due to API limitations.