Details

      Description

      Currently eZ Publish is only using plain text or MD5 for password hash, this improvement implements the usage of BCRYPT to improve the security of the stored passwords.

      It uses PHP's PASSWORD_DEFAULT as default algorithm, meaning that BCRYPT may be replaced by something else in the future.

      NB: This expands the password_hash DB column from 50 to 255 characters, to make room for the bigger hash, and future expansions.

        Issue Links

          Activity

          Show
          Pedro Resende (Inactive) added a comment - - edited https://github.com/ezsystems/ezpublish-kernel/pull/1388 (closed) https://github.com/ezsystems/ezpublish-kernel/pull/1592 Also: https://github.com/ezsystems/ezpublish-legacy/pull/1195
          Show
          Bertrand Dunogier added a comment - - edited Integration tests: https://github.com/ezsystems/ezpublish-kernel/pull/1527 (closed) ref https://github.com/ezsystems/ezpublish-kernel/pull/1561 (merged)
          Hide
          Yannick Roger (Inactive) added a comment -

          Sending this back to InputQ has no one seems to be actively working on it.

          Show
          Yannick Roger (Inactive) added a comment - Sending this back to InputQ has no one seems to be actively working on it.
          Hide
          André Rømcke added a comment -

          Current PR, awaiting 7.0 as it will otherwise break leagacy: https://github.com/ezsystems/ezpublish-kernel/pull/1592

          Show
          André Rømcke added a comment - Current PR, awaiting 7.0 as it will otherwise break leagacy: https://github.com/ezsystems/ezpublish-kernel/pull/1592
          Show
          Gunnstein Lye added a comment - Updated PRs New stack: https://github.com/ezsystems/ezpublish-kernel/pull/2095 Legacy: https://github.com/ezsystems/ezpublish-legacy/pull/1322
          Show
          Gunnstein Lye added a comment - Merged: https://github.com/ezsystems/ezpublish-kernel/commit/9a7c988e6d339136a829e4d5970e924a4d37fc98 https://github.com/ezsystems/ezpublish-legacy/commit/430df048919f840d6c5c67a068073a0cc616e7b9
          Show
          Gunnstein Lye added a comment - Update doc PR: https://github.com/ezsystems/developer-documentation/pull/78

            People

            • Assignee:
              Unassigned
              Reporter:
              Pedro Resende (Inactive)
            • Votes:
              0 Vote for this issue
              Watchers:
              5 Start watching this issue

              Dates

              • Created:
                Updated:
                Resolved:

                Time Tracking

                Estimated:
                Original Estimate - Not Specified
                Not Specified
                Remaining:
                Remaining Estimate - 0 minutes
                0m
                Logged:
                Time Spent - 4 days, 5 hours, 35 minutes
                4d 5h 35m