Umbraco-CMS icon indicating copy to clipboard operation
Umbraco-CMS copied to clipboard

Fixes #12972 for validating legacy member passwords

Open busrasengul opened this issue 2 years ago • 1 comments

Umbraco has the MemberPasswordHasher which then calls LegacyPasswordSecurity.

This successfully validates the correct legacy password hash and returns true.

As it's a legacy password the MemberPasswordHasher returns PasswordVerificationResult.SuccessRehashNeeded which seems helpful because it allows you to perform different logic.

But UmbracoUserManager checks this method returns PasswordVerificationResult.Success to determine if the password is valid. Therefore it's always false for every legacy password.

The MemberManager should check both Success or SuccessRehashNeeded states when validating a password.

If this isn't suitable perhaps there should be a config that allows this check (off by default).

busrasengul avatar Sep 09 '22 12:09 busrasengul

Hi there @busrasengul, thank you for this contribution! 👍

While we wait for one of the Core Collaborators team to have a look at your work, we wanted to let you know about that we have a checklist for some of the things we will consider during review:

  • It's clear what problem this is solving, there's a connected issue or a description of what the changes do and how to test them
  • The automated tests all pass (see "Checks" tab on this PR)
  • The level of security for this contribution is the same or improved
  • The level of performance for this contribution is the same or improved
  • Avoids creating breaking changes; note that behavioral changes might also be perceived as breaking
  • If this is a new feature, Umbraco HQ provided guidance on the implementation beforehand
  • [x] 💡 The contribution looks original and the contributor is presumably allowed to share it

Don't worry if you got something wrong. We like to think of a pull request as the start of a conversation, we're happy to provide guidance on improving your contribution.

If you realize that you might want to make some changes then you can do that by adding new commits to the branch you created for this work and pushing new commits. They should then automatically show up as updates to this pull request.

Thanks, from your friendly Umbraco GitHub bot 🤖 🙂

github-actions[bot] avatar Sep 09 '22 12:09 github-actions[bot]

Thank you @mikecp This has been addressed now 👍

busrasengul avatar Sep 26 '22 13:09 busrasengul

Thanks @busrasengul for the update! It's all ready to be merged now 😃

mikecp avatar Sep 26 '22 22:09 mikecp