A different question (maybe another issue?).
Have you considered the OWASP recommendations for password storage?
Would it make sense to have an opinionated module that users can use and get Tempel with pre-configured options following OWASP recommendations ?
I know some people who do compliance find these certifications / recommendations very important.
I know they change over time so adding the year in the name would make it easy to check and switch: :owasp-2024-xxx .
Moving a question from @ieugen below:
A different question (maybe another issue?). Have you considered the OWASP recommendations for password storage? Would it make sense to have an opinionated module that users can use and get Tempel with pre-configured options following OWASP recommendations ?
I know some people who do compliance find these certifications / recommendations very important. I know they change over time so adding the year in the name would make it easy to check and switch: :owasp-2024-xxx .
https://cheatsheetseries.owasp.org/cheatsheets/Password_Storage_Cheat_Sheet.html#maximum-password-lengths