Page MenuHomePhabricator

Rename wikimedia/password-blacklist library
Open, Needs TriagePublic

Description

"Blacklist" is a problematic term, and not descriptive. Why are these bad passwords?

Event Timeline

cscott created this task.Jun 8 2020, 6:29 PM
Restricted Application added a subscriber: Aklapper. · View Herald TranscriptJun 8 2020, 6:30 PM
Reedy added a subscriber: Reedy.Jun 8 2020, 6:36 PM

common-passwords or something probably works going forward, as per

PasswordBlacklist is a password blacklist implemented to provide NIST best practices of black listing the 100,000 most used passwords.

We need a phab project for this library.

common-passwords sounds good to me. If we think it's likely we add in another list of passwords in the future, then maybe password-list?

Technically, to rename the library we need to update composer.json with the new name, putting the old name in replace, submit the new library to packagist and abandon the old one. And then our own side of things to rename the git repo, CI, docs, etc.

Reedy added a comment.Jun 8 2020, 10:54 PM

password-list seems odd; why would you have a list of passwords.. :)

ill-advised-passwords, forbidden-passwords, rejected-passwords, stop-using-that-password...

I suspect we could have other password lists later, or larger ones etc.

Reedy claimed this task.Jun 8 2020, 11:20 PM

Anyway. Decide on a name and I'll clean this one up seeing as I named it originally

We need a phab project for this library.

Feel free to request one if its maintainers/code stewards agree.

Any further ideas/suggestions on what the new name should be? :)

common-passwords or common-password-denylist. Shrug.

Change 604705 had a related patch set uploaded (by Reedy; owner: Reedy):
[mediawiki/libs/CommonPasswords@master] Rename library to CommonPasswords

https://gerrit.wikimedia.org/r/604705

Change 604706 had a related patch set uploaded (by Reedy; owner: Reedy):
[integration/config@master] Add CommonPasswords to CI

https://gerrit.wikimedia.org/r/604706

Change 604707 had a related patch set uploaded (by Reedy; owner: Reedy):
[integration/config@master] Remove PasswordBlacklist from CI

https://gerrit.wikimedia.org/r/604707

Change 604706 merged by jenkins-bot:
[integration/config@master] Add CommonPasswords to CI

https://gerrit.wikimedia.org/r/604706

Change 604705 merged by jenkins-bot:
[mediawiki/libs/CommonPasswords@master] Rename library to CommonPasswords

https://gerrit.wikimedia.org/r/604705

Change 604721 had a related patch set uploaded (by Reedy; owner: Reedy):
[mediawiki/vendor@master] Replace password-blacklist with common-passwords

https://gerrit.wikimedia.org/r/604721

Change 604726 had a related patch set uploaded (by Reedy; owner: Reedy):
[mediawiki/core@master] Replace password-blacklist with common-passwords

https://gerrit.wikimedia.org/r/604726

Change 604727 had a related patch set uploaded (by Reedy; owner: Reedy):
[mediawiki/core@master] Deprecate PasswordNotInLargeBlacklist

https://gerrit.wikimedia.org/r/604727

Change 604729 had a related patch set uploaded (by Reedy; owner: Reedy):
[mediawiki/libs/CommonPasswords@master] Remove PasswordBlacklist compat

https://gerrit.wikimedia.org/r/604729

Change 604707 merged by jenkins-bot:
[integration/config@master] Remove PasswordBlacklist from CI

https://gerrit.wikimedia.org/r/604707

Mentioned in SAL (#wikimedia-releng) [2020-06-11T14:44:33Z] <Reedy> rm -rf doc1001:/srv/docroot/org/wikimedia/doc/mediawiki-libs-PasswordBlacklist T254799

Reedy updated the task description. (Show Details)Thu, Jun 11, 2:50 PM
Reedy updated the task description. (Show Details)

Change 604721 merged by jenkins-bot:
[mediawiki/vendor@master] Replace password-blacklist with common-passwords

https://gerrit.wikimedia.org/r/604721

Change 604726 merged by jenkins-bot:
[mediawiki/core@master] Replace password-blacklist with common-passwords

https://gerrit.wikimedia.org/r/604726

Change 604727 merged by jenkins-bot:
[mediawiki/core@master] Deprecate PasswordNotInLargeBlacklist

https://gerrit.wikimedia.org/r/604727

Reedy updated the task description. (Show Details)Mon, Jun 15, 9:40 PM

Change 604729 merged by jenkins-bot:
[mediawiki/libs/CommonPasswords@master] Remove PasswordBlacklist compat

https://gerrit.wikimedia.org/r/604729

Change 605980 had a related patch set uploaded (by Reedy; owner: Reedy):
[mediawiki/core@master] Deprecate PasswordCannotMatchBlacklist

https://gerrit.wikimedia.org/r/605980