? ? Success

User tests: Successful: Unsuccessful:

avatar Hackwar
Hackwar
12 Jan 2014

This PR changes the Joomla password hashing infrastructure to using the password_hash() method and thus bcrypt for hashing the password.

I tested this code with PHPass passwords, bcrypt passwords and MD5 passwords with and without salt. All passwords are correctly changed to bcrypt and login is working. You also get an error when you use the wrong password.

avatar Hackwar Hackwar - open - 12 Jan 2014
avatar mbabker
mbabker - comment - 12 Jan 2014

Whomever commits this, please remember to merge to 3.3-dev and not staging.

avatar Hackwar Hackwar - change - 31 Jan 2014
Title
Implementing bcrypt for password hashing into Joomla as default method
[3.3] Implementing bcrypt for password hashing into Joomla as default method
Labels Added: ? ? ?
avatar mbabker mbabker - reference | - 3 Mar 14
avatar Bakual Bakual - close - 3 Mar 2014
avatar Bakual
Bakual - comment - 3 Mar 2014

Closing as merged into 3.3-dev branch

avatar Bakual Bakual - change - 3 Mar 2014
Status New Closed
Closed_Date 0000-00-00 00:00:00 2014-03-03 07:32:05
avatar Bakual Bakual - close - 3 Mar 2014
avatar MaxOnTheHill
MaxOnTheHill - comment - 31 Mar 2014

so this is going into 3.3 release ???

avatar Bakual
Bakual - comment - 31 Mar 2014

so this is going into 3.3 release ???

Answer:

Closing as merged into 3.3-dev branch

Yes, it's already merged into the 3.3 branch. So if nobody detects a problem with it, it will be in the 3.3 release.

avatar Bakual Bakual - reference | 92bad0e - 12 May 14
avatar Hackwar Hackwar - head_ref_deleted - 10 Dec 2014

Add a Comment

Login with GitHub to post a comment