spring-projects / spring-projects/spring-security
Consider changing default encoder in PasswordEncoderFactories
Nobody has claimed this yet.
- Dominant language
- Java
- Stars
- 9.6k
- Forks
- 6.3k
- Avg merge
- 2d 11h
- Merged PRs (30d)
- 52
Description
The default PasswordEncoder in PasswordEncoderFactories is BCryptPasswordEncoder.
We should consider changing the default to another PasswordEncoder based on the recommendations in OWASP Password Storage Cheat Sheet.
Contributor guide
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
Research direction
Start with PasswordEncoderFactories and its default PasswordEncoder, then read the linked OWASP Password Storage Cheat Sheet recommendations. Compare the current BCryptPasswordEncoder choice with the recommended alternatives and determine the required scope before making a change. Done means the default decision is implemented with appropriate verification and the resulting behavior is clear.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- java
- Domain
- authentication, security
- Issue type
- Feature
- Difficulty
- 5/5
- Estimated time
- Over a week
- Activity status
- Stale
- Clarity
- Needs clarification
- Newbie friendliness
- 25/100