IPasswordBreachChecker

Ecng.Net

Checks whether a password appears in any known data breach corpus. Implementations should fail open (treat transient/network errors as "not breached") so an outage does not lock users out of password-gated flows.

Methods

IsBreachedAsync
public Task<bool> IsBreachedAsync(string password, CancellationToken cancellationToken)
result = iPasswordBreachChecker.IsBreachedAsync(password, cancellationToken)

Returns when the password is present in a known breach corpus and should be refused; on a miss or on a transient failure.

password
The plaintext password to check.
cancellationToken
CancellationToken.