Luke Taylor (Migrated from SEC-1688) said:
Ultimately, we will deprecate the use of a SaltSource in favour of random salt and the simpler PasswordEncoder interface. With this in mind, we need to allow injection of the latter into DaoAuthenticationProvider. This will require that the core classes depend on the crypto module.
Luke Taylor said:
The class now takes either type via the setPasswordEncoder. It uses an adapter to convert the crypto version to one of the former encoders.