apple / password-manager-resources

A place for creators and users of password managers to collaborate on resources to make password management better.
MIT License
4.15k stars 448 forks source link

link to password changing standard #77

Open pabs3 opened 4 years ago

pabs3 commented 4 years ago

The README.md alludes to standard mechanisms for password changing etc but doesn't reference any of them. @WICG has published one such standard, it would be good to link to it. If there are other ones, please link to them too.

https://wicg.github.io/change-password-url/ https://github.com/WICG/change-password-url https://news.ycombinator.com/item?id=18618193

Unfortunately it doesn't appear to allow one-click password changing within browser password lists, but it is a good start.

rmondello commented 4 years ago

The README does link to the Well-Known Change Password URL like this:

This is the quirks version of the Well Known URL for Changing Passwords.

But just because it’s mentioned there doesn’t mean it can’t be mentioned more clearly or more often. Do you have any suggestions?

pabs3 commented 4 years ago

Woops, I completely missed that link, thanks. I would suggest creating a Standards section between the Welcome and Resources sections.

-- bye, pabs

https://wiki.debian.org/PaulWise

AndiCui commented 4 years ago

@rmondello I think you are definitely right with “it can be clearer”. A best practice sections will be helpful for ones wanting to get their domains off the list.

mdaniel commented 3 years ago

That link is now 404 (as is the entire https://wicg.github.io/ page); perhaps the link should be updated to https://web.dev/change-password-url/#set-up-%22a-well-known-url-for-changing-passwords%22 (which also still points to the missing spec URL, but at least isn't a huge 404 page)?

pabs3 commented 3 years ago

The change password URL spec moved to the W3C WebAppSec WG:

https://w3c.github.io/webappsec-change-password-url/ https://github.com/w3c/webappsec-change-password-url

-- bye, pabs

https://bonedaddy.net/pabs3/

rmondello commented 3 years ago

I just fixed that here: https://github.com/apple/password-manager-resources/commit/10b1d696bc77614b6d87dd1a366863cdb0de90cf