[django/django] 0317ed: Revert "[1.4.x] Ensure that passwords are never lo...

3 views
Skip to first unread message

GitHub

unread,
Sep 24, 2013, 3:20:58 PM9/24/13
to django-...@googlegroups.com
Branch: refs/heads/stable/1.4.x
Home: https://github.com/django/django
Commit: 0317edf0c7779902d49c6efb8242af61e5569cde
https://github.com/django/django/commit/0317edf0c7779902d49c6efb8242af61e5569cde
Author: Florian Apolloner <flo...@apolloner.eu>
Date: 2013-09-24 (Tue, 24 Sep 2013)

Changed paths:
M django/contrib/auth/forms.py
M django/contrib/auth/hashers.py
M django/contrib/auth/tests/hashers.py

Log Message:
-----------
Revert "[1.4.x] Ensure that passwords are never long enough for a DoS."

This reverts commit 3f3d887a6844ec2db743fee64c9e53e04d39a368.

This fix is no longer necessary, our pbkdf2 (see next commit) implementation
no longer rehashes the password every iteration.


Commit: e2403db95a494c0660ef09f94d9fca1604111be2
https://github.com/django/django/commit/e2403db95a494c0660ef09f94d9fca1604111be2
Author: Florian Apolloner <flo...@apolloner.eu>
Date: 2013-09-24 (Tue, 24 Sep 2013)

Changed paths:
M django/utils/crypto.py

Log Message:
-----------
[1.4.x] Fixed #21138 -- Increased the performance of our PBKDF2 implementation.

Thanks go to Michael Gebetsroither for pointing out this issue and help on
the patch.

Backport of 68540fe4df44492571bc610a0a043d3d02b3d320 from master.


Compare: https://github.com/django/django/compare/ca77e38d243c...e2403db95a49
Reply all
Reply to author
Forward
0 new messages