Hash password when reset it (#3026)

This commit is contained in:
Naoki Takezoe
2022-03-29 07:16:12 +09:00
committed by GitHub
parent b5ee6431c4
commit 8c4ce5e5f4

View File

@@ -693,7 +693,7 @@ trait AccountControllerBase extends AccountManagementControllerBase {
decodeResetPasswordToken(form.token)
.flatMap { mailAddress =>
getAccountByMailAddress(mailAddress).map { account =>
updateAccount(account.copy(password = form.password))
updateAccount(account.copy(password = pbkdf2_sha256(form.password)))
html.resetcomplete()
}
}