<feed xmlns='http://www.w3.org/2005/Atom'>
<title>delta/python-packages/passlib.git/docs/password_hash_api.rst, branch stable</title>
<subtitle>foss.heptapod.net: python-libs/passlib
</subtitle>
<link rel='alternate' type='text/html' href='http://91.123.203.49/cgit/delta/python-packages/passlib.git/'/>
<entry>
<title>bugfix: docs: added sphinx 'orphan' flag to silence errors about redirect pages.</title>
<updated>2016-11-21T02:15:12+00:00</updated>
<author>
<name>Eli Collins</name>
<email>elic@assurancetechnologies.com</email>
</author>
<published>2016-11-21T02:15:12+00:00</published>
<link rel='alternate' type='text/html' href='http://91.123.203.49/cgit/delta/python-packages/passlib.git/commit/?id=de00a1fff81e78c8be8f5cd071e6382f55ea9a12'/>
<id>de00a1fff81e78c8be8f5cd071e6382f55ea9a12</id>
<content type='text'>
</content>
<content type='xhtml'>
<div xmlns='http://www.w3.org/1999/xhtml'>
<pre>
</pre>
</div>
</content>
</entry>
<entry>
<title>docs: followup to prior commit -- adds stub pages so not to break inbound links.</title>
<updated>2016-11-20T19:12:15+00:00</updated>
<author>
<name>Eli Collins</name>
<email>elic@assurancetechnologies.com</email>
</author>
<published>2016-11-20T19:12:15+00:00</published>
<link rel='alternate' type='text/html' href='http://91.123.203.49/cgit/delta/python-packages/passlib.git/commit/?id=fb55b9de6cbb88e0fe13bd60570f80ee2d1d3f89'/>
<id>fb55b9de6cbb88e0fe13bd60570f80ee2d1d3f89</id>
<content type='text'>
</content>
<content type='xhtml'>
<div xmlns='http://www.w3.org/1999/xhtml'>
<pre>
</pre>
</div>
</content>
</entry>
<entry>
<title>docs: LARGE update to documentation, tutorials added, pages relocated</title>
<updated>2016-11-20T19:11:35+00:00</updated>
<author>
<name>Eli Collins</name>
<email>elic@assurancetechnologies.com</email>
</author>
<published>2016-11-20T19:11:35+00:00</published>
<link rel='alternate' type='text/html' href='http://91.123.203.49/cgit/delta/python-packages/passlib.git/commit/?id=a54c5ba533592f7113fd3a4a86bf8a036baa7860'/>
<id>a54c5ba533592f7113fd3a4a86bf8a036baa7860</id>
<content type='text'>
* moved a bunch of pages into 'docs/narr' narrative subsection.
  added placeholder pages in old locations, to minimize inbound link breakage.

* split history into separate pages, was getting way too long.
  removed toplevel CHANGES file, not feasible under new structure.

* passlib.ifc split into reference &amp; tutorial portions,
  tutorial allowed subsuming a bunch of other hash-usage examples.

* added standard fragments for warning about insecure hashes,
  added them to top of a LOT of hash doc pages.

* updated references, various layout tweaks
</content>
<content type='xhtml'>
<div xmlns='http://www.w3.org/1999/xhtml'>
<pre>
* moved a bunch of pages into 'docs/narr' narrative subsection.
  added placeholder pages in old locations, to minimize inbound link breakage.

* split history into separate pages, was getting way too long.
  removed toplevel CHANGES file, not feasible under new structure.

* passlib.ifc split into reference &amp; tutorial portions,
  tutorial allowed subsuming a bunch of other hash-usage examples.

* added standard fragments for warning about insecure hashes,
  added them to top of a LOT of hash doc pages.

* updated references, various layout tweaks
</pre>
</div>
</content>
</entry>
<entry>
<title>docs: large reorganization of documentation</title>
<updated>2016-07-29T17:08:11+00:00</updated>
<author>
<name>Eli Collins</name>
<email>elic@assurancetechnologies.com</email>
</author>
<published>2016-07-29T17:08:11+00:00</published>
<link rel='alternate' type='text/html' href='http://91.123.203.49/cgit/delta/python-packages/passlib.git/commit/?id=e8bb0ffb84a6e5bc3ebb2af21c90ccc64d97b2cb'/>
<id>e8bb0ffb84a6e5bc3ebb2af21c90ccc64d97b2cb</id>
<content type='text'>
* reordering into 'narrative' and 'reference' sections,
  to take advantage of 'fulltoc' extension making
  all pages visible in sidebar.

* styling updates, requires latest cloud_sptheme

* wording improvements to various bits of content
</content>
<content type='xhtml'>
<div xmlns='http://www.w3.org/1999/xhtml'>
<pre>
* reordering into 'narrative' and 'reference' sections,
  to take advantage of 'fulltoc' extension making
  all pages visible in sidebar.

* styling updates, requires latest cloud_sptheme

* wording improvements to various bits of content
</pre>
</div>
</content>
</entry>
<entry>
<title>docs: cleaned up language &amp; links</title>
<updated>2016-07-01T02:50:56+00:00</updated>
<author>
<name>Eli Collins</name>
<email>elic@assurancetechnologies.com</email>
</author>
<published>2016-07-01T02:50:56+00:00</published>
<link rel='alternate' type='text/html' href='http://91.123.203.49/cgit/delta/python-packages/passlib.git/commit/?id=feb706eeba448569162baac79278746fde7a5da0'/>
<id>feb706eeba448569162baac79278746fde7a5da0</id>
<content type='text'>
</content>
<content type='xhtml'>
<div xmlns='http://www.w3.org/1999/xhtml'>
<pre>
</pre>
</div>
</content>
</entry>
<entry>
<title>passlib.hash: Improved handling of hashes which truncate passwords</title>
<updated>2016-06-29T15:43:07+00:00</updated>
<author>
<name>Eli Collins</name>
<email>elic@assurancetechnologies.com</email>
</author>
<published>2016-06-29T15:43:07+00:00</published>
<link rel='alternate' type='text/html' href='http://91.123.203.49/cgit/delta/python-packages/passlib.git/commit/?id=501ee83d2602e497e704760c97b6916ef2633888'/>
<id>501ee83d2602e497e704760c97b6916ef2633888</id>
<content type='text'>
* Added PasswordHash.truncate_size info attribute, to detect hashes
  which truncate the password.

* All such hashes (bcrypt, des_crypt, some others) now accept a "truncate_error"
  option, allowing them to be switched from silent truncation to throwing
  an error instead.  This option is also supported by CryptContext.

* tests/HandlerCase:

    - removed .secret_size config flag, can now just read handler.truncate_size instead.
    - reworked truncation tests to use new API, and test 'truncate_error' policy support.
</content>
<content type='xhtml'>
<div xmlns='http://www.w3.org/1999/xhtml'>
<pre>
* Added PasswordHash.truncate_size info attribute, to detect hashes
  which truncate the password.

* All such hashes (bcrypt, des_crypt, some others) now accept a "truncate_error"
  option, allowing them to be switched from silent truncation to throwing
  an error instead.  This option is also supported by CryptContext.

* tests/HandlerCase:

    - removed .secret_size config flag, can now just read handler.truncate_size instead.
    - reworked truncation tests to use new API, and test 'truncate_error' policy support.
</pre>
</div>
</content>
</entry>
<entry>
<title>Enhanced disabled hash management</title>
<updated>2016-06-26T20:20:04+00:00</updated>
<author>
<name>Eli Collins</name>
<email>elic@assurancetechnologies.com</email>
</author>
<published>2016-06-26T20:20:04+00:00</published>
<link rel='alternate' type='text/html' href='http://91.123.203.49/cgit/delta/python-packages/passlib.git/commit/?id=7c8af0a27ca1a8dbfec8aca488ad68608e7f05c5'/>
<id>7c8af0a27ca1a8dbfec8aca488ad68608e7f05c5</id>
<content type='text'>
* PasswordHash.is_disabled flag now present, to programmatically detect
  disabled hashers (unix_disabled, etc)

* CryptContext now offers methods for disabling, enabling, and testing
  hashes to see if they're tied to a real hash or not.

* disabled hashers now offer .disable() and .enable() helpers,
  as backend for CryptContext methods.

* django_disabled now appends random alphanumeric string, per Django.

* adjusted HandlerCase:
    - checks handler.is_disabled,
    - handle django_disabled via disabled_contains_salt flag
    - tests .disable() and .enable() api if present
</content>
<content type='xhtml'>
<div xmlns='http://www.w3.org/1999/xhtml'>
<pre>
* PasswordHash.is_disabled flag now present, to programmatically detect
  disabled hashers (unix_disabled, etc)

* CryptContext now offers methods for disabling, enabling, and testing
  hashes to see if they're tied to a real hash or not.

* disabled hashers now offer .disable() and .enable() helpers,
  as backend for CryptContext methods.

* django_disabled now appends random alphanumeric string, per Django.

* adjusted HandlerCase:
    - checks handler.is_disabled,
    - handle django_disabled via disabled_contains_salt flag
    - tests .disable() and .enable() api if present
</pre>
</div>
</content>
</entry>
<entry>
<title>docs: replaced a bunch of :meth:`encrypt` references</title>
<updated>2016-06-17T22:47:56+00:00</updated>
<author>
<name>Eli Collins</name>
<email>elic@assurancetechnologies.com</email>
</author>
<published>2016-06-17T22:47:56+00:00</published>
<link rel='alternate' type='text/html' href='http://91.123.203.49/cgit/delta/python-packages/passlib.git/commit/?id=9a70f30e42dfb35efcea0f38d11597cfb22bd7a3'/>
<id>9a70f30e42dfb35efcea0f38d11597cfb22bd7a3</id>
<content type='text'>
</content>
<content type='xhtml'>
<div xmlns='http://www.w3.org/1999/xhtml'>
<pre>
</pre>
</div>
</content>
</entry>
<entry>
<title>renamed PasswordHandler.replace() back to PasswordHandler.using()</title>
<updated>2016-06-15T22:07:59+00:00</updated>
<author>
<name>Eli Collins</name>
<email>elic@assurancetechnologies.com</email>
</author>
<published>2016-06-15T22:07:59+00:00</published>
<link rel='alternate' type='text/html' href='http://91.123.203.49/cgit/delta/python-packages/passlib.git/commit/?id=ce23c2ab15e70b612cbd902bf0513c0cf6d734e9'/>
<id>ce23c2ab15e70b612cbd902bf0513c0cf6d734e9</id>
<content type='text'>
this basically reversed rev 5c41b0153d4f; after using it a bit more,
decided the name didn't indicate as well what the method was doing.
</content>
<content type='xhtml'>
<div xmlns='http://www.w3.org/1999/xhtml'>
<pre>
this basically reversed rev 5c41b0153d4f; after using it a bit more,
decided the name didn't indicate as well what the method was doing.
</pre>
</div>
</content>
</entry>
<entry>
<title>PasswordHash.hash() api shift: deprecating passing settings kwds into hash() --</title>
<updated>2016-06-15T21:43:31+00:00</updated>
<author>
<name>Eli Collins</name>
<email>elic@assurancetechnologies.com</email>
</author>
<published>2016-06-15T21:43:31+00:00</published>
<link rel='alternate' type='text/html' href='http://91.123.203.49/cgit/delta/python-packages/passlib.git/commit/?id=713c0bb81f3cec4ee15715657c627a9757a2edf2'/>
<id>713c0bb81f3cec4ee15715657c627a9757a2edf2</id>
<content type='text'>
callers should use handler.replace(**settings).hash() instead.

this is being done because it greatly streamlines the internals of the .hash()
implementation, and allows some redundant configuration parsing to be extracted
from the .hash() methods and merged in with existing code in .replace().

this also opens things up for alternate code architectures for implementing new hashers,
making it easier to wrap existing libraries (e.g. argon2).

internals
---------
* replaced a bunch of internal .hash(**settings) calls

* GenericHandler
    - stripped out 'relaxed' keyword from constructor, since it's no longer
      passed by hash() etc.
    - _norm_checksum() now only invoked if checksum is specified (simplifies logic).
      keeping support for 'relaxed' mode, but only as explicit keyword.
    - removed some unused comments about .from_string() &amp; .to_string()

* HasSalt mixin:
    - .replace() now supports 'salt' keyword, creates variant
      which has a fixed salt string.

    - 'salt size' keyword removed from ctor, now handled by .replace() call

    - _norm_salt() converted to class method so it can be
       used by .replace() 'salt' keyword code.

    - per-instance bits of _norm_salt() relocated to HasSalt.__init__ proper

    - _generate_salt() converted to class method, since no longer depends on instance config.

* HasRounds mixin:

    - similar to HasSalt, relocates per-instance bits of _norm_rounds()
      into HasRounds.__init__() proper.

    - remainder of _norm_rounds() turned into class method, merged
      with ._clip_to_valid_rounds() helper to reduce duplication.

    - _generate_rounds() converted to class method, since no longer depends on instance config.

hashers
-------
* fshp: added support for 'variant' keyword to replace()
* unix_disabled: added support for 'marker' keyword to replace(), added UTs.
* cisco_type7: to match HasSalt, added support for 'salt' keyword to replace(), added UTs.
* sha256/512_crypt: now uses custom salt &amp; rounds parsing, rather than relaxed kwd,
  to handle correctable-but-invalid config strings.

unittests
---------
* removed checks for PasslibConfigWarning when setting hash(rounds=) out of policy bounds,
  since that now *is* setting the policy.
* adapted some handler ctor to deal w/ lack of 'relaxed' kwd

docs
----
* updated docstrings listing hash() keywords for each scheme to list them
  as .replace() keywords.
* updated example code to use .replace()
* fleshed out api docs about the change
</content>
<content type='xhtml'>
<div xmlns='http://www.w3.org/1999/xhtml'>
<pre>
callers should use handler.replace(**settings).hash() instead.

this is being done because it greatly streamlines the internals of the .hash()
implementation, and allows some redundant configuration parsing to be extracted
from the .hash() methods and merged in with existing code in .replace().

this also opens things up for alternate code architectures for implementing new hashers,
making it easier to wrap existing libraries (e.g. argon2).

internals
---------
* replaced a bunch of internal .hash(**settings) calls

* GenericHandler
    - stripped out 'relaxed' keyword from constructor, since it's no longer
      passed by hash() etc.
    - _norm_checksum() now only invoked if checksum is specified (simplifies logic).
      keeping support for 'relaxed' mode, but only as explicit keyword.
    - removed some unused comments about .from_string() &amp; .to_string()

* HasSalt mixin:
    - .replace() now supports 'salt' keyword, creates variant
      which has a fixed salt string.

    - 'salt size' keyword removed from ctor, now handled by .replace() call

    - _norm_salt() converted to class method so it can be
       used by .replace() 'salt' keyword code.

    - per-instance bits of _norm_salt() relocated to HasSalt.__init__ proper

    - _generate_salt() converted to class method, since no longer depends on instance config.

* HasRounds mixin:

    - similar to HasSalt, relocates per-instance bits of _norm_rounds()
      into HasRounds.__init__() proper.

    - remainder of _norm_rounds() turned into class method, merged
      with ._clip_to_valid_rounds() helper to reduce duplication.

    - _generate_rounds() converted to class method, since no longer depends on instance config.

hashers
-------
* fshp: added support for 'variant' keyword to replace()
* unix_disabled: added support for 'marker' keyword to replace(), added UTs.
* cisco_type7: to match HasSalt, added support for 'salt' keyword to replace(), added UTs.
* sha256/512_crypt: now uses custom salt &amp; rounds parsing, rather than relaxed kwd,
  to handle correctable-but-invalid config strings.

unittests
---------
* removed checks for PasslibConfigWarning when setting hash(rounds=) out of policy bounds,
  since that now *is* setting the policy.
* adapted some handler ctor to deal w/ lack of 'relaxed' kwd

docs
----
* updated docstrings listing hash() keywords for each scheme to list them
  as .replace() keywords.
* updated example code to use .replace()
* fleshed out api docs about the change
</pre>
</div>
</content>
</entry>
</feed>
