Repository metrics
- Stars
- (1 star)
- PR merge metrics
- (PR metrics pending)
Description
Is your feature request related to a problem? Please describe. Right now, although we use PBKDF2 with a SHA512 hash, we use a static salt and static iteration count. This makes things not quite as secure as they could/should be. We also can't easily increase the iteration count for future purposes.
Describe the solution you'd like We need something more like what Django does: https://github.com/django/django/blob/136ec9b62bd0b105f281218d7cad54b7db7a4bab/django/contrib/auth/hashers.py#L247-L299
In the decode method you can see:
algorithm, iterations, salt, hash = encoded.split('$', 3)
This indicates that passwords are stored in the format:
pbdkf2_sha512$260000$random_string_for_salt$hashed_password
Currently, we only share the last part of that; the hashed_password.