douji6199 2014-01-13 03:26 采纳率: 100%
浏览 27
已采纳

忘记密码功能 - 检索和邮件 - symfony2

I want to implement the forgot password functionality. I don't want to change the password. Rather I simply want to mail the password to the provided email address.

But how can I get the decoded password and mail it to the email address?

All I have got till now from SO and other links is the password change process. I don't want that. I can't find any example regarding this. I'm using following encoder:

algorithm:        sha512
encode_as_base64: true
iterations:       1

Please help...

  • 写回答

1条回答 默认 最新

  • douyinyi7766 2014-01-13 03:32
    关注

    Short answer: You can't, and that is a VERY GOOD THING.

    Hashes apply one-way only transformations in order to protect the original password. This is to protect the security of the password in the case of a security breach (computationally costly operations are required to find a hash collision). This is a mathematical property of a hash (sha512 is a hashing algorithm) and cannot be countered.

    In fact, security auditors often verify that the reset password functionality of a website doesn't return the original password they set.

    The only way to allow Symfony2 to do that would be to create your own encoder. However, not hashing your user's password would be a glaring security risk.

    I would also recommend you increase the amount of iterations used to hash the password (to strengthen the hash) and/or switch to bcrypt. A fast hash is a bad hash.

    本回答被题主选为最佳回答 , 对您是否有帮助呢?
    评论

报告相同问题?

悬赏问题

  • ¥50 MATLAB实现圆柱体容器内球形颗粒堆积
  • ¥15 python如何将动态的多个子列表,拼接后进行集合的交集
  • ¥20 vitis-ai量化基于pytorch框架下的yolov5模型
  • ¥15 如何实现H5在QQ平台上的二次分享卡片效果?
  • ¥15 python爬取bilibili校园招聘网站
  • ¥30 求解达问题(有红包)
  • ¥15 请解包一个pak文件
  • ¥15 不同系统编译兼容问题
  • ¥100 三相直流充电模块对数字电源芯片在物理上它必须具备哪些功能和性能?
  • ¥30 数字电源对DSP芯片的具体要求