History Password Hash
It encodes password history information in a list of password hashes.
The plugin can be configured to base64-encode the resulting hash value.
Note that this plugin does also implement the extension point PasswordHash, i.e. it can be used to verify passwords. Further, the plugin can operate on both plain hash values without history and on hash values produced by itself containing history information. Thus, the plugin can be used when introducing the password history on existing data (without password history) without having to migrate the data.
The code verifying passwords must not know of the new concept "password history". The changing a password (or setting one), however, must use the corresponding methods of extension point "PasswordHashWithHistory".
passwordHash) Since the hash value of the configured password hash plugin is considered binary data in any case and base64-encoding is added later (optional, see other configuration property), it does not make much sense to use a password hash function that returns a base64-encoded hash value. It will work but it will make the resulting hash value longer.
encodeBase64) maxHistoryLength) Defines the maximum number of passwords stored in the history for a single user.
A value of 5, for example, means that the five most recently set passwords are stored, excluding the currently hashed password.
Note that the maximum size of the password history is also limited by the capacity of the "pwd_hash" column in the table "medusa_user". To ensure that users do not run into errors when trying to change their password, you should set the history length low enough to avoid exceeding the character limit of the "pwd_hash" database column. By default, this is a limit of 4000 characters.
Some password hash algorithms (for example, encrypted hashes) produce much longer entries for the password history than others.
caseInsensitiveStorage) This feature is implemented by simply converting the passwords to uppercase before hashing them.
alsoTryUpperCase) If enabled, user-supplied passwords will not only be checked exactly as entered but also in uppercase to allow case-insensitive matching.
Leave this setting enabled when disabling case insensitive storage later on to still recognize the previously stored passwords.
type: PasswordHistoryHash
id: PasswordHistoryHash-xxxxxx
displayName:
comment:
properties:
alsoTryUpperCase: false
caseInsensitiveStorage: false
encodeBase64: true
maxHistoryLength: 5
passwordHash: