TurboPanel Docs
Security

Password safety

Two things stand between an account and a weak password: a structural rule the control plane enforces on every path that sets a password, and a breached-password check against Have I Been Pwned (HIBP).

The rule the control plane enforces

Install, sign-up and password reset all validate the password server-side, so a direct API call cannot bypass what the form asks for:

RuleValue
Length8 to 256 characters
Must containat least one digit, and at least one of $ ! @ % & * # ^ ( ) _ + = -
Must notstart or end with whitespace

A password that fails returns 400 with the first failing rule as its message (Password must include at least one number, …). The upper bound exists because Argon2id's cost grows with input length; an unbounded password would make hashing an attacker-controlled expense.

The breached-password check

The control plane checks the password against HIBP's range API wherever a password is set — sign-up, invitation sign-up, password reset and change password — and refuses a known-breached one with 400 password_breached (That password has appeared in a known data breach. Please choose a different one.). The sign-up form also checks in the browser first, so most people see the refusal before they submit.

Your password never leaves the control plane

The password is hashed with SHA-1 (only for this query — storage uses Argon2id) and only the first five hex characters of that hash are sent to api.pwnedpasswords.com/range/, with response padding requested. The returned suffixes are compared locally (k-anonymity). Neither the password nor the full hash is sent or logged.

The check fails open: if HIBP cannot be reached within about two seconds (a self-hosted control plane may be offline), the password is allowed and a warning is logged, rather than blocking sign-up or recovery. A change-password screen exists under Account → Security; see Account security.

  • Account security — two-factor, passkeys, linked providers, re-authentication.
  • Security — control plane and daemon security.
Edit on GitHub

Last updated on

On this page