You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
This commit was created on GitHub.com and signed with GitHub’s verified signature.
Release Notes
Password breach checking. Checks stored passwords against the Have I Been Pwned corpus by sending a 20-bit hash prefix, comparing locally. Off by default; a toolbar badge shows when it's active. Available from a vault-wide report, any password field, the record editor, and the password generator. A failed lookup reports could not check — never a clean result.
Content-Security-Policy relaxed to permit exactly one host, with tests asserting nothing else can be added.
Both reports are actionable. Click a group in Reused Passwords, or an entry in Breached Passwords, to select those records in the main window.
Preference defaults unified. prefs.js kept its own copy and had drifted from prefs-model.js since v2.3.0 — three preferences, including the search-oracle fix, had no default in the running application at all and worked only because undefined is falsy.
Entropy estimate understands dictionary words. Takes the lower of a character estimate and a word estimate, so a passphrase is scored as words. Generator defaults raised to 5 words and 30 characters so PAM no longer produces passwords its own checker rejects.
Table of contents open by default, and a stale documentation disclaimer removed.
Fixed memorable passwords, used a non-cryptographic generator