Uploaded image for project: 'Causeway'
  1. Causeway
  2. CAUSEWAY-2995

[Task] Verify IsisModuleSecurityBypass does bypass Password Hash Generation

    XMLWordPrintableJSON

Details

    • Task
    • Status: Closed
    • Major
    • Resolution: Done
    • 2.0.0-M7
    • 2.0.0-M8
    • Core
    • None

    Description

      Even when IsisModuleSecurityBypass.class is included in DemoAppWicketJpa, BCrypt action are logged to the console (using parameters: -Xms1G -Djava.security.egd=file:///dev/./urandom -Djava.security.debug="provider,engine=SecureRandom")

      See: https://the-asf.slack.com/archives/CFC42LWBV/p1649400664122289?thread_ts=1648577147.703919&cid=CFC42LWBV

      Attachments

        Activity

          People

            hobrom Andi Huber
            joerg.rade Jörg Rade
            Votes:
            0 Vote for this issue
            Watchers:
            3 Start watching this issue

            Dates

              Created:
              Updated:
              Resolved: