Skip to content

Consider changing default encoder in PasswordEncoderFactories #16879

Open
@jgrandja

Description

@jgrandja

The default PasswordEncoder in PasswordEncoderFactories is BCryptPasswordEncoder.

We should consider changing the default to another PasswordEncoder based on the recommendations in OWASP Password Storage Cheat Sheet.

Metadata

Metadata

Assignees

No one assigned

    Labels

    for: team-attentionThis ticket should be discussed as a team before proceedingtype: enhancementA general enhancement

    Type

    No type

    Projects

    No projects

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions