##// END OF EJS Templates
security: limit the maximum password lenght to 72 characters to prevent possible...
security: limit the maximum password lenght to 72 characters to prevent possible server side resource consumption attack. - bcrypt heavy computation can lead to DOS using a very long password .eg 10**8 lenght. - we allowed this on registration or on password update

File last commit:

r1:854a839a default
r2128:f22a9ea9 default
Show More
auth.rst
37 lines | 995 B | text/x-rst | RstLexer

Authentication Options

|RCE| provides a built in authentication plugin rhodecode.lib.auth_rhodecode. This is enabled by default and accessed through the administrative interface. Additionally, |RCE| provides a Pluggable Authentication System (PAS). This gives the administrator greater control over how users authenticate with the system.

Important

You can disable the built in |RCM| authentication plugin rhodecode.lib.auth_rhodecode and force all authentication to go through your authentication plugin. However, if you do this, and your external authentication tools fails, you will be unable to access |RCM|.

|RCM| comes with the following user authentication management plugins: