[django/django] 1cc572: Revert "[1.5.x] Ensure that passwords are never lo...

3 views
Skip to first unread message

GitHub

unread,
Sep 24, 2013, 3:15:42 PM9/24/13
to django-...@googlegroups.com
Branch: refs/heads/stable/1.5.x
Home: https://github.com/django/django
Commit: 1cc572a071003583f15cdbca2f5b4d910ebd3504
https://github.com/django/django/commit/1cc572a071003583f15cdbca2f5b4d910ebd3504
Author: Florian Apolloner <flo...@apolloner.eu>
Date: 2013-09-24 (Tue, 24 Sep 2013)

Changed paths:
M django/contrib/auth/forms.py
M django/contrib/auth/hashers.py
M django/contrib/auth/tests/hashers.py

Log Message:
-----------
Revert "[1.5.x] Ensure that passwords are never long enough for a DoS."

This reverts commit 22b74fa09d7ccbc8c52270d648a0da7f3f0fa2bc.

This fix is no longer necessary, our pbkdf2 (see next commit) implementation
no longer rehashes the password every iteration.


Commit: f3853172a4bde963ff9908870bc2ea53eb73bc04
https://github.com/django/django/commit/f3853172a4bde963ff9908870bc2ea53eb73bc04
Author: Florian Apolloner <flo...@apolloner.eu>
Date: 2013-09-24 (Tue, 24 Sep 2013)

Changed paths:
M django/utils/crypto.py

Log Message:
-----------
[1.5.x] Fixed #21138 -- Increased the performance of our PBKDF2 implementation.

Thanks go to Michael Gebetsroither for pointing out this issue and help on
the patch.

Backport of 68540fe4df44492571bc610a0a043d3d02b3d320 from master.


Compare: https://github.com/django/django/compare/de8715ca9749...f3853172a4bd
Reply all
Reply to author
Forward
0 new messages