Uploaded image for project: 'OpenId Connect'
  1. OpenId Connect
  2. OIDC-127

The token is not always salted when stored

    XMLWordPrintable

Details

    • Bug
    • Resolution: Fixed
    • Major
    • 1.32.1
    • 1.15
    • Provider
    • None
    • Unknown

    Description

      While OIDC-41 did introduce everything required to support and manipulate salted stored tokens, they are not actually salted in practice.

      Since OIDC-41 also changed the type of that field to password, only admins can access the value, so the impact is very limited in practice but would still be better to go all the way.

      Attachments

        Activity

          People

            tmortagne Thomas Mortagne
            tmortagne Thomas Mortagne
            Votes:
            0 Vote for this issue
            Watchers:
            1 Start watching this issue

            Dates

              Created:
              Updated:
              Resolved: