Homec4science

Make password hashing modular

Authored by epriestley <git@epriestley.com> on Feb 18 2014, 18:31.

Description

Make password hashing modular

Summary:
Ref T4443. Make hashing algorithms pluggable and extensible so we can deal with the attendant complexities more easily.

This moves "Iterated MD5" to a modular implementation, and adds a tiny bit of hack-glue so we don't need to migrate the DB in this patch. I'll migrate in the next patch, then add bcrypt.

Test Plan:

  • Verified that the same stuff gets stored in the DB (i.e., no functional changes):
    • Logged into an old password account.
    • Changed password.
    • Registered a new account.
    • Changed password.
    • Switched back to master.
    • Logged in / out, changed password.
    • Switched back, logged in.
  • Ran unit tests (they aren't super extensive, but cover some of the basics).

Reviewers: btrahan

Reviewed By: btrahan

CC: aran, kofalt

Maniphest Tasks: T4443

Differential Revision: https://secure.phabricator.com/D8268

Details

Committed
epriestley <git@epriestley.com>Feb 18 2014, 23:09
Pushed
aubortJan 31 2017, 17:16
Parents
rPH2eeef339bf01: Add crumbs to calendar
Branches
Unknown
Tags
Unknown

Event Timeline

epriestley <git@epriestley.com> committed rPH3c9153079f13: Make password hashing modular (authored by epriestley <git@epriestley.com>).Feb 18 2014, 23:09