Skip to content

Add shared credentials for HDFC Bank (hdfcbank.com → hdfc.bank.in) - #1239

Merged
rmondello merged 1 commit into
apple:mainfrom
mangeshraut712:mangeshraut712/feat/hdfc-bank-shared-credentials
Sep 2, 2026
Merged

rmondello merged 1 commit into
apple:mainfrom
mangeshraut712:mangeshraut712/feat/hdfc-bank-shared-credentials

Conversation

@mangeshraut712

Copy link
Copy Markdown
Contributor

Summary

HDFC Bank rebranded its public site to hdfc.bank.in and now serves NetBanking at now.hdfc.bank.in, while many bookmarks, reset/register links, and saved passwords still use hdfcbank.com. This PR:

  1. Adds a from/to shared-credentials group so passwords saved for hdfcbank.com autofill on hdfc.bank.in.
  2. Copies the existing hdfc.bank.in IPIN rule onto hdfcbank.com (same 8–15 policy).

This is one bank only (HDFC). No change-password URL: the remaining reset pages are OTP flows, not a logged-in password change page, and netbanking.hdfcbank.com is Cloudflare-challenged from some networks.

Shared credentials evidence (live, 2026-09-02)

Login on hdfcbank.com redirects to hdfc.bank.in:

  • https://now.hdfcbank.com/ → 301 https://now.hdfc.bank.in/ → 302 https://now.hdfc.bank.in/retail-app/ (200, title Welcome to HDFC Bank NetBanking).
  • https://netbanking.hdfcbank.com/netbanking/ → 308 https://now.hdfc.bank.in/ → same retail-app login.

That matches CONTRIBUTING’s from/to case (from domains redirect to to to log in). fromDomainsAreObsoleted is true because those login hostnames no longer serve the form themselves.

Official site still treats both names as HDFC NetBanking:

  • https://www.hdfc.bank.in/ LOGIN menu lists NetBanking. CSP default-src / frame-ancestors explicitly allow *.hdfcbank.com and *.hdfc.bank.in.
  • Interstitial https://v.hdfc.bank.in/assets/popuppages/netbanking.html (live 200):
    • Proceed Now: https://now.hdfc.bank.in/retail-app/
    • Regenerate IPIN: https://netbanking.hdfcbank.com/netbanking/IpinResetUsingOTP.htm
    • Register: https://netbanking.hdfcbank.com/netbanking/registrationUsingOTP.htm
  • Homepage still also links to https://netbanking.hdfc.bank.in/netbanking/ (that hostname currently has no public DNS) and the same interstitial.

shared would be wrong: hdfcbank.com NetBanking URLs do not keep a login form; they bounce to now.hdfc.bank.in.

Password rules evidence

Existing quirk for hdfc.bank.in (merged in #1138):
minlength: 8; maxlength: 15; required: digit; required: upper, lower; allowed: [@&:|.^~#_$!)?];

This PR applies the same string to hdfcbank.com so generation stays consistent across the shared backend.

Live T&C (https://www.hdfc.bank.in/resources/way-to-bank/online-banking/net-banking/terms-and-conditions, section 1.15 IPIN):

Choose an IPIN which shall be at least of 6 characters long or such minimum number as may be specified by the Bank from time to time and shall consist of a mix of alphabets, numbers and special characters…

The T&C floor (6) is weaker than the registration UI. Credit-card registration CCUserReg.html (Wayback 2025-04-15 of https://netbanking.hdfcbank.com/netbanking/CCUserReg.html) stated min 8 / max 15, mix of alphabets, numbers, special characters, case-sensitive; client JS used minlen=8, maxlen=15 and rejected %, ;, ", '. That matches the existing hdfc.bank.in quirk (8–15, digit + letter, limited specials). The live now.hdfc.bank.in/retail-app/ SPA is a Customer ID login (password collected after ID); it does not contradict the 8–15 IPIN cap.

The rule was parsed with this repo’s PasswordRulesParser.js (min 8, max 15, required digit, required upper-or-lower, allowed specials). I did not submit generated IPINs into a live reset/register form: those hdfcbank.com pages return Cloudflare 403 from this environment and require OTP + debit-card details.

Overall Checklist

for password-rules.json

  • The given rule isn't particularly standard and obvious for password managers
  • Generated passwords have been tested from this rule using the Password Rules Validation Tool (same rule already merged for hdfc.bank.in in Add password rules for hdfc.bank.in #1138; parser in this repo accepts it)
  • Information has been included about the website's requirements (live T&C quote, Wayback registration UI, redirects)
  • The PR isn't documenting something that would be a common practice among password managers (e.g. minimal length of 6)

for shared-credentials.json

  • There's evidence the domains are currently related (live redirects, official interstitial links, CSP, same NetBanking product)
  • If using from and to, the from domain(s) redirect to the to domain to log in.

NetBanking login on hdfcbank.com now redirects to now.hdfc.bank.in,
while the official site and interstitial still advertise both domains.
Share credentials from hdfcbank.com to hdfc.bank.in and apply the same
8–15 IPIN rule already documented for hdfc.bank.in.

Signed-off-by: Mangesh Raut <mbr63@drexel.edu>
@rmondello
rmondello merged commit 0c47ded into apple:main Sep 2, 2026
5 checks passed
@rmondello

Copy link
Copy Markdown
Contributor

Thank you for all of the liveness information and justification.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants