ekbhard / Java-Spring

University project made with Spring framework
0 stars 0 forks source link

По конфигурации и в целом #9

Open whenafirestartstoburn opened 4 years ago

whenafirestartstoburn commented 4 years ago

https://github.com/ekbhard/Java-Spring/blob/master/src/main/java/com/sb/JavaWithSpring/config/WebSecurityConfig.java

Открываем документацию https://docs.spring.io/spring-security/site/docs/4.2.13.RELEASE/apidocs/org/springframework/security/crypto/password/NoOpPasswordEncoder.html, читаем -

Deprecated. This PasswordEncoder is not secure.

и ниже:

This PasswordEncoder is provided for legacy and testing purposes only and is not considered secure.

Делаем вывод - нужно использовать другой PasswordEncoder, напр. БКрипт.

whenafirestartstoburn commented 4 years ago

.iml/.idea и пр. - это все надо игнорировать, конечно, в git-е не должно быть