fix(auth): retire le bouton mort PASSWORD_ALGO (argon2id fixe dans le code) #29
No reviewers
Labels
No labels
auto-merge
No milestone
No project
No assignees
1 participant
Notifications
Due date
No due date set.
Dependencies
No dependencies set.
Reference: AcadeNice/corentin_wakdo#29
Loading…
Add table
Reference in a new issue
No description provided.
Delete branch "fix/remove-dead-password-algo"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Finding LOW (audit 2026-06-16)
PASSWORD_ALGOetait expose (.env.example+docker-compose.yml) comme si l'algorithme de hashage etait configurable, maisPasswordHashercodePASSWORD_ARGON2IDen dur. PoserPASSWORD_ALGO=bcryptn'aurait eu aucun effet : faux levier, risque de fausse confiance dans une config inactive.Correctif
argon2id = choix security-by-design non configurable. Var retiree de
.env.exampleetdocker-compose.yml; intention documentee dansPasswordHasher::hash. Les COUTS (ARGON2_MEMORY/TIME/THREADS) restent regables et honores. Aucun code ne lisaitPASSWORD_ALGO-> pas de changement de comportement.Pas de label auto-merge.