douji6199 2014-01-13 03:26 采纳率: 100%
浏览 27
已采纳

忘记密码功能 - 检索和邮件 - symfony2

I want to implement the forgot password functionality. I don't want to change the password. Rather I simply want to mail the password to the provided email address.

But how can I get the decoded password and mail it to the email address?

All I have got till now from SO and other links is the password change process. I don't want that. I can't find any example regarding this. I'm using following encoder:

algorithm:        sha512
encode_as_base64: true
iterations:       1

Please help...

  • 写回答

1条回答 默认 最新

  • douyinyi7766 2014-01-13 03:32
    关注

    Short answer: You can't, and that is a VERY GOOD THING.

    Hashes apply one-way only transformations in order to protect the original password. This is to protect the security of the password in the case of a security breach (computationally costly operations are required to find a hash collision). This is a mathematical property of a hash (sha512 is a hashing algorithm) and cannot be countered.

    In fact, security auditors often verify that the reset password functionality of a website doesn't return the original password they set.

    The only way to allow Symfony2 to do that would be to create your own encoder. However, not hashing your user's password would be a glaring security risk.

    I would also recommend you increase the amount of iterations used to hash the password (to strengthen the hash) and/or switch to bcrypt. A fast hash is a bad hash.

    本回答被题主选为最佳回答 , 对您是否有帮助呢?
    评论

报告相同问题?

悬赏问题

  • ¥15 组策略中的计算机配置策略无法下发
  • ¥15 如何绘制动力学系统的相图
  • ¥15 对接wps接口实现获取元数据
  • ¥20 给自己本科IT专业毕业的妹m找个实习工作
  • ¥15 用友U8:向一个无法连接的网络尝试了一个套接字操作,如何解决?
  • ¥30 我的代码按理说完成了模型的搭建、训练、验证测试等工作(标签-网络|关键词-变化检测)
  • ¥50 mac mini外接显示器 画质字体模糊
  • ¥15 TLS1.2协议通信解密
  • ¥40 图书信息管理系统程序编写
  • ¥20 Qcustomplot缩小曲线形状问题