Commit cb1e779c authored by Tim Graham's avatar Tim Graham
Browse files

Refs #24115 -- Added docs for password updates on bcrypt rounds change.

parent 134ca4d4
Loading
Loading
Loading
Loading
+7 −3
Original line number Diff line number Diff line
@@ -191,8 +191,13 @@ can switch to new (and better) storage algorithms as they get invented.
However, Django can only upgrade passwords that use algorithms mentioned in
:setting:`PASSWORD_HASHERS`, so as you upgrade to new systems you should make
sure never to *remove* entries from this list. If you do, users using
unmentioned algorithms won't be able to upgrade. Passwords will be upgraded
when changing the PBKDF2 iteration count.
unmentioned algorithms won't be able to upgrade. Hashed passwords will be
updated when increasing (or decreasing) the number of PBKDF2 iterations or
bcrypt rounds.

.. versionchanged:: 1.9

    Passwords updates when changing the number of bcrypt rounds was added.

.. _sha1: https://en.wikipedia.org/wiki/SHA1
.. _pbkdf2: https://en.wikipedia.org/wiki/PBKDF2
@@ -200,7 +205,6 @@ when changing the PBKDF2 iteration count.
.. _bcrypt: https://en.wikipedia.org/wiki/Bcrypt
.. _`bcrypt library`: https://pypi.python.org/pypi/bcrypt/


Manually managing a user's password
===================================