Uploaded image for project: 'Cassandra'
  1. Cassandra
  2. CASSANDRA-13626

Check hashed password matches expected bcrypt hash format before checking

Log workAgile BoardRank to TopRank to BottomAttach filesAttach ScreenshotBulk Copy AttachmentsBulk Move AttachmentsVotersWatch issueWatchersCreate sub-taskConvert to sub-taskMoveLinkCloneLabelsUpdate Comment AuthorReplace String in CommentUpdate Comment VisibilityDelete Comments
    XMLWordPrintableJSON

Details

    • Low

    Description

      We use Bcrypt.checkpw in the auth subsystem, but do a reasonably poor job of guaranteeing that the hashed password we send to it is really a hashed password, and checkpw does an even worse job of failing nicely. We should at least sanity check the hash complies with the expected format prior to validating.

      Attachments

        Activity

          This comment will be Viewable by All Users Viewable by All Users
          Cancel

          People

            jjirsa Jeff Jirsa Assign to me
            jjirsa Jeff Jirsa
            Jeff Jirsa
            Sam Tunnicliffe
            Votes:
            0 Vote for this issue
            Watchers:
            4 Start watching this issue

            Dates

              Created:
              Updated:
              Resolved:

              Slack

                Issue deployment