Skip to content

Commit

Permalink
[1.6.x] Removed 1.6 release note text regarding password limit length.
Browse files Browse the repository at this point in the history
This changed was reverted in 5d74853.

Backport of d97bec5 from master
  • Loading branch information
timgraham committed Oct 17, 2013
1 parent b2f9c74 commit 37afcbe
Showing 1 changed file with 0 additions and 16 deletions.
16 changes: 0 additions & 16 deletions docs/releases/1.6.txt
Original file line number Diff line number Diff line change
Expand Up @@ -810,22 +810,6 @@ as JSON requires string keys, you will likely run into problems if you are
using non-string keys in ``request.session``. See the
:ref:`session_serialization` documentation for more details.

4096-byte limit on passwords
~~~~~~~~~~~~~~~~~~~~~~~~~~~~

.. note::
This behavior was also added in the Django 1.5.4 and 1.4.8 security
releases.

Historically, Django has imposed no length limit on plaintext
passwords. This enables a denial-of-service attack through submission
of bogus but extremely large passwords, tying up server resources
performing the (expensive, and increasingly expensive with the length
of the password) calculation of the corresponding hash.

Django now imposes a 4096-byte limit on password length, and will fail
authentication with any submitted password of greater length.

Miscellaneous
~~~~~~~~~~~~~

Expand Down

0 comments on commit 37afcbe

Please sign in to comment.