[wp-trac] [WordPress Trac] #33904: user_activation_key is too short causing password reset process to break when using bcrypt

WordPress Trac noreply at wordpress.org
Fri Oct 9 13:19:58 UTC 2015


#33904: user_activation_key is too short causing password reset process to break
when using bcrypt
--------------------------+------------------------------
 Reporter:  tomdxw        |       Owner:
     Type:  defect (bug)  |      Status:  new
 Priority:  normal        |   Milestone:  Awaiting Review
Component:  Users         |     Version:  4.3
 Severity:  normal        |  Resolution:
 Keywords:                |     Focuses:
--------------------------+------------------------------

Comment (by Otto42):

 The size of the password field should probably be increased to 255 for
 future proofing.

 Ref the notes on PASSWORD_DEFAULT here:
 https://secure.php.net/manual/en/function.password-hash.php

--
Ticket URL: <https://core.trac.wordpress.org/ticket/33904#comment:2>
WordPress Trac <https://core.trac.wordpress.org/>
WordPress publishing platform


More information about the wp-trac mailing list