Skip to content

Commit

Permalink
bug #35060 [Security] Fix missing defaults for auto-migrating encoder…
Browse files Browse the repository at this point in the history
…s (chalasr)

This PR was merged into the 4.4 branch.

Discussion
----------

[Security] Fix missing defaults for auto-migrating encoders

| Q             | A
| ------------- | ---
| Branch?       | 4.4
| Bug fix?      | yes
| New feature?  | no
| Deprecations? | no
| Tickets       | Fixes #35058
| License       | MIT
| Doc PR        | -

Commits
-------

665ef06 [Security] Fix missing defaults for auto-migrating encoders
  • Loading branch information
chalasr committed Dec 26, 2019
2 parents aac9ca2 + 665ef06 commit fd81bb8
Show file tree
Hide file tree
Showing 2 changed files with 11 additions and 6 deletions.
12 changes: 6 additions & 6 deletions src/Symfony/Component/Security/Core/Encoder/EncoderFactory.php
Expand Up @@ -144,10 +144,10 @@ private function getEncoderConfigFromAlgorithm(array $config): array
return [
'class' => Pbkdf2PasswordEncoder::class,
'arguments' => [
$config['hash_algorithm'],
$config['encode_as_base64'],
$config['iterations'],
$config['key_length'],
$config['hash_algorithm'] ?? 'sha512',
$config['encode_as_base64'] ?? true,
$config['iterations'] ?? 1000,
$config['key_length'] ?? 40,
],
];

Expand Down Expand Up @@ -205,8 +205,8 @@ private function getEncoderConfigFromAlgorithm(array $config): array
'class' => MessageDigestPasswordEncoder::class,
'arguments' => [
$config['algorithm'],
$config['encode_as_base64'],
$config['iterations'],
$config['encode_as_base64'] ?? true,
$config['iterations'] ?? 5000,
],
];
}
Expand Down
Expand Up @@ -162,6 +162,11 @@ public function testDefaultMigratingEncoders()
(new EncoderFactory([SomeUser::class => ['class' => NativePasswordEncoder::class, 'arguments' => []]]))->getEncoder(SomeUser::class)
);

$this->assertInstanceOf(
MigratingPasswordEncoder::class,
(new EncoderFactory([SomeUser::class => ['algorithm' => 'bcrypt', 'cost' => 11]]))->getEncoder(SomeUser::class)
);

if (!SodiumPasswordEncoder::isSupported()) {
return;
}
Expand Down

0 comments on commit fd81bb8

Please sign in to comment.