[TYPO3-v4] Request for comments: Separating password transmission from password comparison

Dmitry Dulepov dmitry.dulepov at gmail.com
Fri Dec 23 13:30:18 CET 2011


Hi!

Helmut Hummel wrote:
> There only minor things that change for external auth-services and what
> changes are improvements or things that a auth-service should not rely on.

This is actually a huge change. I know several clients, who implemented 
their own auth services and those will break. Tell them, they should not 
rely on something, they used for years and you will show them the straight 
road to Drupal.

-- 
Dmitry Dulepov
TYPO3 core&security teams member
Blog: http://dmitry-dulepov.com/
Twitter: http://twitter.com/dmitryd

Simplicity will save the world.


More information about the TYPO3-project-v4 mailing list