bug #35060 [Security] Fix missing defaults for auto-migrating encoders (chalasr)
This PR was merged into the 4.4 branch.
Discussion
----------
[Security] Fix missing defaults for auto-migrating encoders
| Q | A
| ------------- | ---
| Branch? | 4.4
| Bug fix? | yes
| New feature? | no
| Deprecations? | no
| Tickets | Fixes #35058
| License | MIT
| Doc PR | -
Commits
-------
665ef06013
[Security] Fix missing defaults for auto-migrating encoders
This commit is contained in:
commit
fd81bb8137
@ -144,10 +144,10 @@ class EncoderFactory implements EncoderFactoryInterface
|
|||||||
return [
|
return [
|
||||||
'class' => Pbkdf2PasswordEncoder::class,
|
'class' => Pbkdf2PasswordEncoder::class,
|
||||||
'arguments' => [
|
'arguments' => [
|
||||||
$config['hash_algorithm'],
|
$config['hash_algorithm'] ?? 'sha512',
|
||||||
$config['encode_as_base64'],
|
$config['encode_as_base64'] ?? true,
|
||||||
$config['iterations'],
|
$config['iterations'] ?? 1000,
|
||||||
$config['key_length'],
|
$config['key_length'] ?? 40,
|
||||||
],
|
],
|
||||||
];
|
];
|
||||||
|
|
||||||
@ -205,8 +205,8 @@ class EncoderFactory implements EncoderFactoryInterface
|
|||||||
'class' => MessageDigestPasswordEncoder::class,
|
'class' => MessageDigestPasswordEncoder::class,
|
||||||
'arguments' => [
|
'arguments' => [
|
||||||
$config['algorithm'],
|
$config['algorithm'],
|
||||||
$config['encode_as_base64'],
|
$config['encode_as_base64'] ?? true,
|
||||||
$config['iterations'],
|
$config['iterations'] ?? 5000,
|
||||||
],
|
],
|
||||||
];
|
];
|
||||||
}
|
}
|
||||||
|
@ -162,6 +162,11 @@ class EncoderFactoryTest extends TestCase
|
|||||||
(new EncoderFactory([SomeUser::class => ['class' => NativePasswordEncoder::class, 'arguments' => []]]))->getEncoder(SomeUser::class)
|
(new EncoderFactory([SomeUser::class => ['class' => NativePasswordEncoder::class, 'arguments' => []]]))->getEncoder(SomeUser::class)
|
||||||
);
|
);
|
||||||
|
|
||||||
|
$this->assertInstanceOf(
|
||||||
|
MigratingPasswordEncoder::class,
|
||||||
|
(new EncoderFactory([SomeUser::class => ['algorithm' => 'bcrypt', 'cost' => 11]]))->getEncoder(SomeUser::class)
|
||||||
|
);
|
||||||
|
|
||||||
if (!SodiumPasswordEncoder::isSupported()) {
|
if (!SodiumPasswordEncoder::isSupported()) {
|
||||||
return;
|
return;
|
||||||
}
|
}
|
||||||
|
Reference in New Issue
Block a user