Skip to content

Fixed - Use secure "password encoder" implementation#148

Open
noegomezz wants to merge 10 commits into
rmartinsanta:mainfrom
paaul19:Use-secure-"PasswordEncoder"-implementation

Hidden character warning

The head ref may contain hidden characters: "Use-secure-"PasswordEncoder"-implementation"
Open

Fixed - Use secure "password encoder" implementation#148
noegomezz wants to merge 10 commits into
rmartinsanta:mainfrom
paaul19:Use-secure-"PasswordEncoder"-implementation

Conversation

@noegomezz
Copy link
Copy Markdown

Se ha parcheado la vulnerabilidad que implicaba el uso de un password encoder que no realizaba ninguna operación con las contraseñas. Se sustituye el uso de NoOpPasswordEncoder, que almacenaba contraseñas en texto plano, por BCryptPasswordEncoder, siguiendo las recomendaciones de seguridad de SonarQube para garantizar el hashing y salting de las credenciales de usuario.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants