Security warnings for Yesod.Auth.HashDB #668

This commit is contained in:
Michael Snoyman 2014-02-22 19:21:59 +02:00
parent 0ab2fc21fd
commit 98b64cd17c

View File

@ -18,6 +18,11 @@
-- Stability : Stable
-- Portability : Portable
--
-- /WARNING/: This module was /not/ designed with security in mind, and is not
-- suitable for production sites. In the near future, it will likely be either
-- deprecated or rewritten to have a more secure implementation. For more
-- information, see: <https://github.com/yesodweb/yesod/issues/668>.
--
-- A yesod-auth AuthPlugin designed to look users up in Persist where
-- their user id's and a salted SHA1 hash of their password is stored.
--