mirror of
https://github.com/django/django.git
synced 2025-01-10 10:26:34 +00:00
parent
2847b22f29
commit
aa777cdaaa
@ -146,7 +146,7 @@ algorithm.
|
||||
that ``bcrypt(password_with_100_chars) == bcrypt(password_with_100_chars[:72])``.
|
||||
The original ``BCryptPasswordHasher`` does not have any special handling and
|
||||
thus is also subject to this hidden password length limit.
|
||||
``BCryptSHA256PasswordHasher`` fixes this by first first hashing the
|
||||
``BCryptSHA256PasswordHasher`` fixes this by first hashing the
|
||||
password using sha256. This prevents the password truncation and so should
|
||||
be preferred over the ``BCryptPasswordHasher``. The practical ramification
|
||||
of this truncation is pretty marginal as the average user does not have a
|
||||
|
Loading…
Reference in New Issue
Block a user