Skip to content

[stable35] docs(auth): clarify password storage and length limits - #15657

Open
backportbot[bot] wants to merge 4 commits into
stable35from
backport/15476/stable35
Open

backportbot[bot] wants to merge 4 commits into
stable35from
backport/15476/stable35

Conversation

@backportbot

@backportbot backportbot Bot commented Sep 25, 2026

Copy link
Copy Markdown

Backport of PR #15476

Assisted-by: Copilot:gpt-5.6-sol

Signed-off-by: Josh <josh.t.richards@gmail.com>
Document the 469-byte account-password maximum and distinguish it from the RSA key-size threshold and bcrypt's 72-byte input limitation.

Clarify which requirements administrators can configure and how share passwords differ from account passwords.

Signed-off-by: Josh <josh.t.richards@gmail.com>
Replace tentative language with verified token-storage and validation behavior.

Clarify the consequences of missing recoverable passwords, tighten the security impact statements, and correct password-length boundary wording.

Signed-off-by: Josh <josh.t.richards@gmail.com>
Signed-off-by: Josh <josh.t.richards@gmail.com>
@github-actions

Copy link
Copy Markdown
Contributor

📖 Documentation Preview

🔍 Open preview →

📄 1 changed documentation page

Last updated: Fri, 25 Sep 2026 14:54:40 GMT

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant