[FEATURE] Use salted Install Tool password 39/22739/4
authorNicole Cordes <typo3@cordes.co>
Wed, 31 Jul 2013 22:18:45 +0000 (00:18 +0200)
committerChristian Kuhn <lolli@schwarzbu.ch>
Wed, 28 Aug 2013 08:44:31 +0000 (10:44 +0200)
commitd1199a8880f6cf83371e120a1b82dc46d6b9a9bf
treea747d0ba3ceed24aae70f71e6cacd6ae49b28255
parent8f0052e69a788cddfc9f9b6fcd9a8549e693920f
[FEATURE] Use salted Install Tool password

To enhanced the security this patch changes the Install Tool password
from md5 hash to a salted hashed password. Therefore the default
password in the FactoryConfiguration.php is changed. Old md5 hashes get
converted automatically during the boot process of the Install Tool. The
output of the calculated hash is reintroduced when an error occured.
The report modules were adjusted to be able to check salted hashed
passwords.

Resolves: #50613
Releases: 6.2
Change-Id: If02a43780c9c819ebd6da7cbf0acad305f805330
Reviewed-on: https://review.typo3.org/22739
Reviewed-by: Kai Ole Hartwig
Tested-by: Kai Ole Hartwig
Reviewed-by: Christian Kuhn
Tested-by: Christian Kuhn
typo3/sysext/backend/Classes/Utility/BackendUtility.php
typo3/sysext/core/Configuration/FactoryConfiguration.php
typo3/sysext/install/Classes/Controller/AbstractController.php
typo3/sysext/install/Classes/Controller/Action/Step/DatabaseData.php
typo3/sysext/install/Classes/Controller/Action/Tool/ImportantActions.php
typo3/sysext/install/Resources/Private/Partials/Action/Common/LoginForm.html
typo3/sysext/install/Resources/Private/Templates/Action/Common/InstallToolPasswordNotSet.html
typo3/sysext/reports/Classes/Report/Status/SecurityStatus.php