[Security] Fix missing defaults for auto-migrating encoders

This commit is contained in:
Robin Chalas 2019-12-19 23:40:59 +01:00
parent 6dc0c38351
commit 665ef06013
2 changed files with 11 additions and 6 deletions

View File

@ -144,10 +144,10 @@ class EncoderFactory implements EncoderFactoryInterface
return [
'class' => Pbkdf2PasswordEncoder::class,
'arguments' => [
$config['hash_algorithm'],
$config['encode_as_base64'],
$config['iterations'],
$config['key_length'],
$config['hash_algorithm'] ?? 'sha512',
$config['encode_as_base64'] ?? true,
$config['iterations'] ?? 1000,
$config['key_length'] ?? 40,
],
];
@ -205,8 +205,8 @@ class EncoderFactory implements EncoderFactoryInterface
'class' => MessageDigestPasswordEncoder::class,
'arguments' => [
$config['algorithm'],
$config['encode_as_base64'],
$config['iterations'],
$config['encode_as_base64'] ?? true,
$config['iterations'] ?? 5000,
],
];
}

View File

@ -162,6 +162,11 @@ class EncoderFactoryTest extends TestCase
(new EncoderFactory([SomeUser::class => ['class' => NativePasswordEncoder::class, 'arguments' => []]]))->getEncoder(SomeUser::class)
);
$this->assertInstanceOf(
MigratingPasswordEncoder::class,
(new EncoderFactory([SomeUser::class => ['algorithm' => 'bcrypt', 'cost' => 11]]))->getEncoder(SomeUser::class)
);
if (!SodiumPasswordEncoder::isSupported()) {
return;
}