Uh oh!
There was an error while loading.Please reload this page.
- Notifications
You must be signed in to change notification settings - Fork5.3k
[Security] bcrypt is the new default hasher for native/auto#14992
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to ourterms of service andprivacy statement. We’ll occasionally send you account related emails.
Already on GitHub?Sign in to your account
Merged
Uh oh!
There was an error while loading.Please reload this page.
Conversation
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.Learn more about bidirectional Unicode characters
wouterj approved these changesFeb 17, 2021
OskarStark approved these changesFeb 17, 2021
Contributor
OskarStark commentedFeb 17, 2021
Thank you Javier. |
javiereguiluz added a commit that referenced this pull requestJun 11, 2021
…(pableu)This PR was merged into the 5.3 branch.Discussion----------[Security] Update description of password hasher configThe description of the password hashers in the reference isn't up to date for Symfony 5.3."Auto" now always uses bcrypt (see#14980 and#14992), but it wasn't reflected here. I initially thought this was a bug in the password hasher component itself and created asymfony/symfony#41646, but I've since learned that the switch to bcrypt was intentional :-)I updated all the hasher descriptions a bit and removed the part about sodium before PHP 7.2 because Symfony 5.3 requires PHP >= 7.2. I also added an extra paragraph for the bcrypt hasher because it was a bit mixed into the description of the "auto" hasher.Commits-------d404d19 [Security] update description of password hasher config
Sign up for freeto join this conversation on GitHub. Already have an account?Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Fixes#14980.