View Issue Details

IDProjectCategoryView StatusLast Update
0004952Composrcorepublic2022-10-06 00:01
ReporterChris GrahamAssigned To 
SeverityFeature-request 
Status non-assignedResolutionopen 
Product Version 
Fixed in Version 
Summary0004952: Implement known password change URL
DescriptionW3C has made a spec for specifying a known URL to change a user's password.
It is designed to make it easier to do mass-password-changes after a user finds they are breached.

https://w3c.github.io/webappsec-change-password-url/

Implement this as a simple redirect in recommended.htaccess.

Update tut_webapp to reference the spec.
TagsType: Security, Type: Standards compliance
Time estimation (hours)0.5
Sponsorship open

Activities

There are no notes attached to this issue.

Issue History

Date Modified Username Field Change
2022-09-27 17:28 Chris Graham New Issue
2022-09-27 17:28 Chris Graham Tag Attached: Type: Security
2022-09-27 17:28 Chris Graham Tag Attached: Type: Standards compliance
2022-10-06 00:01 Chris Graham Description Updated View Revisions