Merge branch '3.3.x'

This commit is contained in:
Marc Alexander 2020-01-30 21:38:35 +01:00
commit c221858fab
No known key found for this signature in database
GPG key ID: 50E0D2423696F995
3 changed files with 7 additions and 7 deletions

View file

@ -1,7 +1,7 @@
parameters: parameters:
passwords.driver.argon2_memory_cost: 1024 passwords.driver.argon2_memory_cost: 65536
passwords.driver.argon2_threads: 2 passwords.driver.argon2_threads: 2
passwords.driver.argon2_time_cost: 2 passwords.driver.argon2_time_cost: 4
passwords.driver.bcrypt_cost: 10 passwords.driver.bcrypt_cost: 10
services: services:

View file

@ -33,7 +33,7 @@ class argon2i extends base_native
* @param int $threads Number of threads to use (optional) * @param int $threads Number of threads to use (optional)
* @param int $time_cost Maximum amount of time (optional) * @param int $time_cost Maximum amount of time (optional)
*/ */
public function __construct(\phpbb\config\config $config, helper $helper, $memory_cost = 1024, $threads = 2, $time_cost = 2) public function __construct(\phpbb\config\config $config, helper $helper, $memory_cost = 65536, $threads = 2, $time_cost = 4)
{ {
parent::__construct($config, $helper); parent::__construct($config, $helper);
@ -42,8 +42,8 @@ class argon2i extends base_native
* See https://wiki.php.net/rfc/sodium.argon.hash and PHPBB3-16266 * See https://wiki.php.net/rfc/sodium.argon.hash and PHPBB3-16266
* Don't allow cost factors to be below default settings where possible * Don't allow cost factors to be below default settings where possible
*/ */
$this->memory_cost = max($memory_cost, defined('PASSWORD_ARGON2_DEFAULT_MEMORY_COST') ? PASSWORD_ARGON2_DEFAULT_MEMORY_COST : 1024); $this->memory_cost = max($memory_cost, defined('PASSWORD_ARGON2_DEFAULT_MEMORY_COST') ? PASSWORD_ARGON2_DEFAULT_MEMORY_COST : 65536);
$this->time_cost = max($time_cost, defined('PASSWORD_ARGON2_DEFAULT_TIME_COST') ? PASSWORD_ARGON2_DEFAULT_TIME_COST : 2); $this->time_cost = max($time_cost, defined('PASSWORD_ARGON2_DEFAULT_TIME_COST') ? PASSWORD_ARGON2_DEFAULT_TIME_COST : 4);
$this->threads = (defined('PASSWORD_ARGON2_PROVIDER') && PASSWORD_ARGON2_PROVIDER == 'sodium') ? $this->threads = (defined('PASSWORD_ARGON2_PROVIDER') && PASSWORD_ARGON2_PROVIDER == 'sodium') ?
PASSWORD_ARGON2_DEFAULT_THREADS : max($threads, defined('PASSWORD_ARGON2_DEFAULT_THREADS') ? PASSWORD_ARGON2_DEFAULT_THREADS : 1); PASSWORD_ARGON2_DEFAULT_THREADS : max($threads, defined('PASSWORD_ARGON2_DEFAULT_THREADS') ? PASSWORD_ARGON2_DEFAULT_THREADS : 1);
} }

View file

@ -24,8 +24,8 @@ class phpbb_passwords_helper_test extends \phpbb_test_case
// Initialize argon2 default options // Initialize argon2 default options
$this->argon2_default_cost_options = [ $this->argon2_default_cost_options = [
'memory_cost' => 1024, 'memory_cost' => 65536,
'time_cost' => 2, 'time_cost' => 4,
'threads' => 2 'threads' => 2
]; ];