🔐 Open source password manager with Nextcloud integration
Перейти к файлу
Nextcloud bot 915956c722
[tx-robot] updated from transifex
2017-03-24 01:14:14 +00:00
appinfo Change dev docs link 2017-02-23 13:49:06 +01:00
controller Code style fixes 2017-02-22 18:02:55 +01:00
css Add feature to request vault destructions 2017-02-22 18:02:55 +01:00
docs Add docs about requesting vaults / credentials 2017-01-12 11:53:47 +01:00
img Fix icon 2016-12-28 16:58:08 +01:00
js Code style fixes 2017-02-22 18:02:55 +01:00
l10n [tx-robot] updated from transifex 2017-03-24 01:14:14 +00:00
lib Code style fixes 2017-02-22 18:02:55 +01:00
middleware Check HTTP_ORIGIN using isset 2017-01-19 13:58:34 +01:00
migration Fixes 2017-01-11 18:09:49 +01:00
sass Add feature to request vault destructions 2017-02-22 18:02:55 +01:00
templates Small fixes 2017-02-22 18:02:55 +01:00
tests Fix tests 2017-02-22 18:02:55 +01:00
.dockerignore Added dockerfile 2016-10-19 18:13:32 +02:00
.drone.yml Rename drone config 2016-10-11 15:40:02 +02:00
.gitignore Update ignore file 2016-12-21 22:07:31 +01:00
.jshintrc Add JSHint, solve all problems 2016-10-07 19:56:29 +02:00
.scrutinizer.yml Revert "Fix failing tests if token is not set" 2017-01-06 13:12:42 +01:00
.travis.yml Travis Fix 2017-02-05 16:52:55 +01:00
AUTHORS.md Initial commit 2016-09-09 17:36:35 +02:00
CHANGELOG.md This fixes the decryption error happening when auto login is enabled and user changes vault password. 2016-12-28 15:26:26 +01:00
CNAME Create CNAME 2017-02-05 17:23:45 +01:00
CONTRIBUTING.md Updaye 2017-03-16 15:41:55 +01:00
COPYING Initial commit 2016-09-09 17:36:35 +02:00
Dockerfile Fix dockerfile and add support for ssl 2017-01-16 14:16:02 +01:00
Gruntfile.js Add feature to request vault destructions 2017-02-22 18:02:55 +01:00
ISSUE_TEMPLATE.md Update 2017-03-16 15:44:56 +01:00
LICENSE Initial commit 2016-09-07 13:30:00 +02:00
Makefile Initial commit 2016-09-09 17:36:35 +02:00
README.md Lock vault after 3 wrong attempts (Fixes #197) 2017-02-17 21:25:18 +01:00
karma.conf.js Add ng-translate to karma 2016-12-20 00:12:29 +01:00
launch_phpunit.sh Top level typos 2017-01-06 17:06:54 +05:45
package.json Add feature to request vault destructions 2017-02-22 18:02:55 +01:00
personal.php Fix missing admin-settings.js 2017-01-18 19:08:59 +01:00
phpunit.integration.xml Initial commit 2016-09-09 17:36:35 +02:00
phpunit.xml Added missing classes to coverage 2016-10-16 20:35:14 +02:00
swagger.yaml Top level typos 2017-01-06 17:06:54 +05:45

README.md

#Passman Passman is a full featured password manager.

Build Status Codacy Badge Codacy Badge Scrutinizer Code Quality

Contents

##Screenshots Logged in to vault

Credential selected

Edit credential

Password tool

For more screenshots: Click here

Features:

  • Vaults
  • Vault key is never sent to the server
  • Credentials are stored with 256 bit AES (see security)
  • Ability to add custom fields to credentials
  • Built-in OTP(One Time Password) generator
  • Password analyzer
  • Share passwords internally and via link in a secure manner.
  • Import from various password managers:
    • KeePass
    • LastPass
    • DashLane
    • ZOHO
    • Clipperz.is
    • EnPass
    • ocPasswords

For a demo of this app visit https://demo.passman.cc

Tested on

  • NextCloud 10 / 11
  • ownCloud 9.1+

External apps

Supported databases

  • SQL Lite*
  • MySQL / MariaDB*

*Tested on travis

Untested databases:

  • pgsql

Security

Password generation

Passman features a build in password generator. Not it only generates passwords, but it also measures their strength using zxcvbn.

Generate passwords as you like

Passwords are generated using the random functions from sjcl.

Storing credentials

All passwords are encrypted client side using sjcl which uses AES-256 bit. Users supply a vault key which is feed into sjcl as encryption key. After the credentials are encrypted they are send to the server, there they will be encrypted again. This time using the following routine:

Sharing credentials.

Passman allows users to share passwords (this can be turned off by an administrator).

API

For developers passman offers an api.

Support Passman

Passman is open source, but we would gladly accept a beer (or pizza!)
Please consider donating via

Code reviews

If you have any improvements regarding our code. Please do the following

  • Clone us
  • Make your edits
  • Add your name to the contributors
  • Send a PR

Or if you're feeling lazy, create an issue, and we'll think about it.

Docker

To run passman with docker you can use docker run -p 8080:80 -p 8443:443 brantje/passman
You have to supply your own ssl certs.
Example:
docker run -p 8080:80 -p 8443:443 -v /directory/cert.pem:/data/ssl/cert.pem -v /directory/cert.key:/data/ssl/cert.key brantje/passman

Development

Passman uses a single .js file for the templates. This gives the benefit that we don't need to request every template with XHR.
For CSS we use SASS so you need ruby and sass installed.
templates.js and the CSS are built with grunt. To watch for changes use grunt watch To run the unit tests install phpunit globally, and setup the environment variables on the launch_phpunit.sh script then just run that script, any arguments passed to this script will be forwarded to phpunit.

Main developers

  • Brantje
  • Animalillo

Contributors

Add yours when creating a pull request!

  • None

FAQ

Are you adding something to check if malicious code is executing on the browser?
No, because malicious code could edit the functions that check for malicious code.