Skip to content

Issue warning to folks using old sha256 hashed password #3560

Closed as not planned
@jsjoeio

Description

@jsjoeio

@jawnsy had a great idea:

I'm not sure where in the code to put it, but it would be nice to issue a warning if someone is using the plain text/cookie/sha256 methods to tell them that their authentication method is insecure, and to consider upgrading to argon2.

See: #3422 (comment)

Will look at after: #3422

Metadata

Metadata

Assignees

Labels

enhancementSome improvement that isn't a featuresecuritySecurity related

Type

No type

Projects

No projects

Milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions