From 5e347e4efaa81c2108256dc927208cd55dc10baa Mon Sep 17 00:00:00 2001 From: Laria Carolin Chabowski Date: Fri, 25 Sep 2020 23:09:31 +0200 Subject: Use password_hash() and friends to hash and verify passwords Previously I rolled my own password hashing function. While it at least used some sort of salt, it's still a terrible idea. The newly created class PasswordHash wraps the password_hash() family of functions but can also check the old password hash format (to distinguish them, the new password hashes are prefixed with a '!'). In PasswordHash::needsRehash we then always report an hash of the old format as being in need of a rehash. That way, these old hashes will be replaced the next time the user successfully logs in. --- ratatoeskr/setup/setup.php | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) (limited to 'ratatoeskr/setup/setup.php') diff --git a/ratatoeskr/setup/setup.php b/ratatoeskr/setup/setup.php index 23205b8..c18fff0 100644 --- a/ratatoeskr/setup/setup.php +++ b/ratatoeskr/setup/setup.php @@ -1,6 +1,7 @@ save(); $admingrp = Group::create("admins"); - $admin = user::create($_POST["admin_username"], PasswordHash::create($_POST["admin_init_password"])); + $admin = User::create($_POST["admin_username"], PasswordHash::hash($_POST["admin_init_password"])); $admin->save(); $admingrp->include_user($admin); -- cgit v1.2.3-70-g09d2