Have I Been Pwned
Reject compromised passwords.
This page documents the current Ruby port behavior. Ruby uses snake_case option names and auth.api method names; HTTP paths and JSON keys keep the upstream wire shape where implemented.
Configure
require "better_auth"
auth = BetterAuth.auth(
secret: ENV.fetch("BETTER_AUTH_SECRET"),
base_url: ENV.fetch("BETTER_AUTH_URL", "http://localhost:3000"),
plugins: [
BetterAuth::Plugins.have_i_been_pwned
]
)Usage
# This plugin hooks into existing auth flows and does not add public endpoints.
# Use the normal sign-up, sign-in, or password routes after configuring it.Routes
This plugin does not add public routes.
Options
Current Ruby options accepted by BetterAuth::Plugins.have_i_been_pwned:
pathsrange_lookupcustom_password_compromised_message
Support Notes
- The examples above are based on Ruby plugin source and tests in
packages/better_auth. - If an upstream section is not represented here, treat it as not yet documented or not yet supported by the Ruby port until the matching Ruby implementation exists.