PwnedPasswordsClient
Ecng.Net
IPasswordBreachChecker backed by the Have I Been Pwned (https://haveibeenpwned.com/API/v3#PwnedPasswords) range API using k-anonymity: only the first 5 chars of the SHA-1 hex hash are sent, the API returns every full hash suffix sharing that prefix, and the match is done locally — the password itself never leaves the process. No API key is required.
Implements: IPasswordBreachChecker
Constructors
PwnedPasswordsClient
public PwnedPasswordsClient(HttpClient http)
pwnedPasswordsClient = PwnedPasswordsClient(http)
Initializes a new instance of the PwnedPasswordsClient class.
- http
- The HTTP client to use. A 5s timeout is applied when none is set.
Properties
MinOccurrences
public int MinOccurrences { get; set; }
value = pwnedPasswordsClient.MinOccurrences
pwnedPasswordsClient.MinOccurrences = value
Minimum number of recorded breach occurrences for a password to be considered unsafe. Defaults to 1 (any appearance).
Methods
IsBreachedAsync
public Task<bool> IsBreachedAsync(string password, CancellationToken cancellationToken)
result = pwnedPasswordsClient.IsBreachedAsync(password, cancellationToken)
Returns when the password is present in a known breach corpus and should be refused; on a miss or on a transient failure.
- password
- The plaintext password to check.
- cancellationToken
- CancellationToken.