Page MenuHomePhabricator

Rename wikimedia/password-blacklist library
Closed, ResolvedPublic

Description

"Blacklist" is a problematic term, and not descriptive. Why are these bad passwords?

Event Timeline

common-passwords or something probably works going forward, as per

PasswordBlacklist is a password blacklist implemented to provide NIST best practices of black listing the 100,000 most used passwords.

We need a phab project for this library.

common-passwords sounds good to me. If we think it's likely we add in another list of passwords in the future, then maybe password-list?

Technically, to rename the library we need to update composer.json with the new name, putting the old name in replace, submit the new library to packagist and abandon the old one. And then our own side of things to rename the git repo, CI, docs, etc.

password-list seems odd; why would you have a list of passwords.. :)

ill-advised-passwords, forbidden-passwords, rejected-passwords, stop-using-that-password...

I suspect we could have other password lists later, or larger ones etc.

Anyway. Decide on a name and I'll clean this one up seeing as I named it originally

We need a phab project for this library.

Feel free to request one if its maintainers/code stewards agree.

Any further ideas/suggestions on what the new name should be? :)

common-passwords or common-password-denylist. Shrug.

Change 604705 had a related patch set uploaded (by Reedy; owner: Reedy):
[mediawiki/libs/CommonPasswords@master] Rename library to CommonPasswords

https://gerrit.wikimedia.org/r/604705

Change 604706 had a related patch set uploaded (by Reedy; owner: Reedy):
[integration/config@master] Add CommonPasswords to CI

https://gerrit.wikimedia.org/r/604706

Change 604707 had a related patch set uploaded (by Reedy; owner: Reedy):
[integration/config@master] Remove PasswordBlacklist from CI

https://gerrit.wikimedia.org/r/604707

Change 604706 merged by jenkins-bot:
[integration/config@master] Add CommonPasswords to CI

https://gerrit.wikimedia.org/r/604706

Change 604705 merged by jenkins-bot:
[mediawiki/libs/CommonPasswords@master] Rename library to CommonPasswords

https://gerrit.wikimedia.org/r/604705

Change 604721 had a related patch set uploaded (by Reedy; owner: Reedy):
[mediawiki/vendor@master] Replace password-blacklist with common-passwords

https://gerrit.wikimedia.org/r/604721

Change 604726 had a related patch set uploaded (by Reedy; owner: Reedy):
[mediawiki/core@master] Replace password-blacklist with common-passwords

https://gerrit.wikimedia.org/r/604726

Change 604727 had a related patch set uploaded (by Reedy; owner: Reedy):
[mediawiki/core@master] Deprecate PasswordNotInLargeBlacklist

https://gerrit.wikimedia.org/r/604727

Change 604729 had a related patch set uploaded (by Reedy; owner: Reedy):
[mediawiki/libs/CommonPasswords@master] Remove PasswordBlacklist compat

https://gerrit.wikimedia.org/r/604729

Change 604707 merged by jenkins-bot:
[integration/config@master] Remove PasswordBlacklist from CI

https://gerrit.wikimedia.org/r/604707

Mentioned in SAL (#wikimedia-releng) [2020-06-11T14:44:33Z] <Reedy> rm -rf doc1001:/srv/docroot/org/wikimedia/doc/mediawiki-libs-PasswordBlacklist T254799

Reedy updated the task description. (Show Details)

Change 604721 merged by jenkins-bot:
[mediawiki/vendor@master] Replace password-blacklist with common-passwords

https://gerrit.wikimedia.org/r/604721

Change 604726 merged by jenkins-bot:
[mediawiki/core@master] Replace password-blacklist with common-passwords

https://gerrit.wikimedia.org/r/604726

Change 604727 merged by jenkins-bot:
[mediawiki/core@master] Deprecate PasswordNotInLargeBlacklist

https://gerrit.wikimedia.org/r/604727

Change 604729 merged by jenkins-bot:
[mediawiki/libs/CommonPasswords@master] Remove PasswordBlacklist compat

https://gerrit.wikimedia.org/r/604729

Change 605980 had a related patch set uploaded (by Reedy; owner: Reedy):
[mediawiki/core@master] Deprecate PasswordCannotMatchBlacklist

https://gerrit.wikimedia.org/r/605980

Reedy removed a project: Patch-For-Review.
Reedy updated the task description. (Show Details)

Change 680008 had a related patch set uploaded (by DannyS712; author: DannyS712):

[mediawiki/libs/CommonPasswords@master] Update references to old name "PasswordBlacklist"

https://gerrit.wikimedia.org/r/680008

PasswordBlacklist is also still listed at https://doc.wikimedia.org/cover/ (along with CommonPasswords - maybe just the old entry needs deletion?) but I couldn't figure out where the data for that comes from

Mentioned in SAL (#wikimedia-operations) [2021-04-16T00:30:57Z] <Krinkle> Delete old data at doc1001:/srv/doc/cover/PasswordBlacklist (ref T254799)

Change 680008 merged by jenkins-bot:

[mediawiki/libs/CommonPasswords@master] Update a few places to use new name "CommonPasswords"

https://gerrit.wikimedia.org/r/680008