[django/django] 50a811: Revert "[1.6.x] Ensure that passwords are never lo...

3 views
Skip to first unread message

GitHub

unread,
Sep 24, 2013, 3:12:03 PM9/24/13
to django-...@googlegroups.com
Branch: refs/heads/stable/1.6.x
Home: https://github.com/django/django
Commit: 50a811a170dfeddd9c27d21aee36801277d21bf3
https://github.com/django/django/commit/50a811a170dfeddd9c27d21aee36801277d21bf3
Author: Florian Apolloner <flo...@apolloner.eu>
Date: 2013-09-24 (Tue, 24 Sep 2013)

Changed paths:
M django/contrib/auth/forms.py
M django/contrib/auth/hashers.py
M django/contrib/auth/tests/test_hashers.py

Log Message:
-----------
Revert "[1.6.x] Ensure that passwords are never long enough for a DoS."

This reverts commit 5ecc0f828ebe270cfc92a0a2bfb4268800907904.

This fix is no longer necessary, our pbkdf2 (see next commit) implementation
no longer rehashes the password every iteration.


Commit: e5dc08f2dbdd8bf67960f0448810d71ba58990b4
https://github.com/django/django/commit/e5dc08f2dbdd8bf67960f0448810d71ba58990b4
Author: Florian Apolloner <flo...@apolloner.eu>
Date: 2013-09-24 (Tue, 24 Sep 2013)

Changed paths:
M django/utils/crypto.py

Log Message:
-----------
[1.6.x] Fixed #21138 -- Increased the performance of our PBKDF2 implementation.

Thanks go to Michael Gebetsroither for pointing out this issue and help on
the patch.

Backport of 68540fe4df44492571bc610a0a043d3d02b3d320 from master.


Compare: https://github.com/django/django/compare/1a922870ea07...e5dc08f2dbdd
Reply all
Reply to author
Forward
0 new messages