Files
seaweedfs/weed
Chris Lu 9b077d6f1f fix(sftpd): replace plaintext password storage with bcrypt hashing
SFTP user passwords were stored as plaintext in the JSON user store.
This replaces plaintext storage with bcrypt hashing:

- Add HashedPassword field to User struct for bcrypt hashes
- SetPassword() now hashes with bcrypt.DefaultCost
- CheckPassword() verifies against bcrypt hash with transparent
  legacy migration: plaintext passwords auto-upgrade on successful login
- CreateUser() uses SetPassword() instead of direct assignment
- ValidatePassword() delegates to CheckPassword() and persists
  migrated hashes

Existing users with plaintext passwords are transparently migrated
to bcrypt on their next successful authentication.
2026-04-01 21:28:24 -07:00
..
2026-03-31 20:53:41 -07:00
2024-02-14 08:26:38 -08:00
2026-04-01 17:42:41 -07:00