Skip to content

Commit

Permalink
[1.7.x] Fixed #24556 -- Added reminder about HTTPS to passwords docs.
Browse files Browse the repository at this point in the history
Backport of 1119063 from master
  • Loading branch information
ssssam authored and timgraham committed Apr 3, 2015
1 parent b9cbf75 commit abd6255
Showing 1 changed file with 8 additions and 0 deletions.
8 changes: 8 additions & 0 deletions docs/topics/auth/passwords.txt
Original file line number Diff line number Diff line change
Expand Up @@ -8,6 +8,14 @@ tools for managing user passwords. This document describes how Django stores
passwords, how the storage hashing can be configured, and some utilities to
work with hashed passwords.

.. seealso::

Even though users may use strong passwords, attackers might be able to
eavesdrop on their connections. Use :ref:`HTTPS
<security-recommendation-ssl>` to avoid sending passwords (or any other
sensitive data) over plain HTTP connections because they will be vulnerable
to password sniffing.

.. _auth_password_storage:

How Django stores passwords
Expand Down

0 comments on commit abd6255

Please sign in to comment.