Skip to content

Commit 5e4fa7c

Browse files
authored
Turn default hash password algorightm back to pbkdf2 from argon2 until we found a better one (#14673)
* Turn default hash password algorightm back to pbkdf2 from argon2 until we found a better one * Add a warning on document
1 parent ed83412 commit 5e4fa7c

File tree

3 files changed

+3
-3
lines changed

3 files changed

+3
-3
lines changed

custom/conf/app.example.ini

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -565,7 +565,7 @@ ONLY_ALLOW_PUSH_IF_GITEA_ENVIRONMENT_SET = true
565565
;Classes include "lower,upper,digit,spec"
566566
PASSWORD_COMPLEXITY = off
567567
; Password Hash algorithm, either "argon2", "pbkdf2", "scrypt" or "bcrypt"
568-
PASSWORD_HASH_ALGO = argon2
568+
PASSWORD_HASH_ALGO = pbkdf2
569569
; Set false to allow JavaScript to read CSRF cookie
570570
CSRF_COOKIE_HTTP_ONLY = true
571571
; Validate against https://haveibeenpwned.com/Passwords to see if a password has been exposed

docs/content/doc/advanced/config-cheat-sheet.en-us.md

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -401,7 +401,7 @@ relation to port exhaustion.
401401
- `IMPORT_LOCAL_PATHS`: **false**: Set to `false` to prevent all users (including admin) from importing local path on server.
402402
- `INTERNAL_TOKEN`: **\<random at every install if no uri set\>**: Secret used to validate communication within Gitea binary.
403403
- `INTERNAL_TOKEN_URI`: **<empty>**: Instead of defining internal token in the configuration, this configuration option can be used to give Gitea a path to a file that contains the internal token (example value: `file:/etc/gitea/internal_token`)
404-
- `PASSWORD_HASH_ALGO`: **argon2**: The hash algorithm to use \[argon2, pbkdf2, scrypt, bcrypt\].
404+
- `PASSWORD_HASH_ALGO`: **pbkdf2**: The hash algorithm to use \[argon2, pbkdf2, scrypt, bcrypt\], argon2 will spend more memory than others.
405405
- `CSRF_COOKIE_HTTP_ONLY`: **true**: Set false to allow JavaScript to read CSRF cookie.
406406
- `MIN_PASSWORD_LENGTH`: **6**: Minimum password length for new users.
407407
- `PASSWORD_COMPLEXITY`: **off**: Comma separated list of character classes required to pass minimum complexity. If left empty or no valid values are specified, checking is disabled (off):

modules/setting/setting.go

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -804,7 +804,7 @@ func NewContext() {
804804
DisableGitHooks = sec.Key("DISABLE_GIT_HOOKS").MustBool(true)
805805
DisableWebhooks = sec.Key("DISABLE_WEBHOOKS").MustBool(false)
806806
OnlyAllowPushIfGiteaEnvironmentSet = sec.Key("ONLY_ALLOW_PUSH_IF_GITEA_ENVIRONMENT_SET").MustBool(true)
807-
PasswordHashAlgo = sec.Key("PASSWORD_HASH_ALGO").MustString("argon2")
807+
PasswordHashAlgo = sec.Key("PASSWORD_HASH_ALGO").MustString("pbkdf2")
808808
CSRFCookieHTTPOnly = sec.Key("CSRF_COOKIE_HTTP_ONLY").MustBool(true)
809809
PasswordCheckPwn = sec.Key("PASSWORD_CHECK_PWN").MustBool(false)
810810

0 commit comments

Comments
 (0)