diff --git a/project/settings/local.py-dist b/project/settings/local.py-dist index 90e1991a..6e31a6c0 100644 --- a/project/settings/local.py-dist +++ b/project/settings/local.py-dist @@ -45,11 +45,20 @@ DEV = True # # Playdoh ships with sha512 password hashing by default. Bcrypt+HMAC is safer, # # so it is recommended. Please read , -# # then switch this to bcrypt and pick a secret HMAC key for your application. -# PWD_ALGORITHM = 'bcrypt' +# # uncomment the bcrypt hasher and pick a secret HMAC key for your application. +# BASE_PASSWORD_HASHERS = ( +# 'django_sha2.hashers.BcryptHMACCombinedPasswordVerifier', +# 'django_sha2.hashers.SHA512PasswordHasher', +# 'django_sha2.hashers.SHA256PasswordHasher', +# 'django.contrib.auth.hashers.SHA1PasswordHasher', +# 'django.contrib.auth.hashers.MD5PasswordHasher', +# 'django.contrib.auth.hashers.UnsaltedMD5PasswordHasher', +# ) # HMAC_KEYS = { # for bcrypt only # '2011-01-01': 'cheesecake', # } +# from django_sha2 import get_password_hashers +# PASSWORD_HASHERS = get_password_hashers(BASE_PASSWORD_HASHERS, HMAC_KEYS) # Make this unique, and don't share it with anybody. It cannot be blank. SECRET_KEY = ''