Browse Source

Document NoOpPasswordEncoder will not be removed

This commit adds extension to deprecation notice.

Fixes gh-8506
pull/8721/head
Dávid Kovács 6 years ago committed by Rob Winch
parent
commit
e8daeacd89
  1. 3
      crypto/src/main/java/org/springframework/security/crypto/password/NoOpPasswordEncoder.java

3
crypto/src/main/java/org/springframework/security/crypto/password/NoOpPasswordEncoder.java

@ -26,7 +26,8 @@ package org.springframework.security.crypto.password; @@ -26,7 +26,8 @@ package org.springframework.security.crypto.password;
* @deprecated This PasswordEncoder is not secure. Instead use an
* adaptive one way function like BCryptPasswordEncoder, Pbkdf2PasswordEncoder, or
* SCryptPasswordEncoder. Even better use {@link DelegatingPasswordEncoder} which supports
* password upgrades.
* password upgrades. There are no plans to remove this support. It is deprecated to indicate that
* this is a legacy implementation and using it is considered insecure.
*/
@Deprecated
public final class NoOpPasswordEncoder implements PasswordEncoder {

Loading…
Cancel
Save