diff --git a/django/contrib/auth/hashers.py b/django/contrib/auth/hashers.py index f7f143b78f..a8583f7dbd 100644 --- a/django/contrib/auth/hashers.py +++ b/django/contrib/auth/hashers.py @@ -349,7 +349,7 @@ class BCryptPasswordHasher(BCryptSHA256PasswordHasher): This hasher does not first hash the password which means it is subject to the 72 character bcrypt password truncation, most use cases should prefer - the BCryptSha512PasswordHasher. + the BCryptSHA256PasswordHasher. See: https://code.djangoproject.com/ticket/20138 """