Skip to content

[stable33] docs(auth): clarify password storage and length limits - #15659

Merged
joshtrichards merged 4 commits into
stable33from
backport/15476/stable33
Sep 27, 2026
Merged

joshtrichards merged 4 commits into
stable33from
backport/15476/stable33

Conversation

@backportbot

@backportbot backportbot Bot commented Sep 25, 2026

Copy link
Copy Markdown

Backport of PR #15476

Assisted-by: Copilot:gpt-5.6-sol

Signed-off-by: Josh <josh.t.richards@gmail.com>
Document the 469-byte account-password maximum and distinguish it from the RSA key-size threshold and bcrypt's 72-byte input limitation.

Clarify which requirements administrators can configure and how share passwords differ from account passwords.

Signed-off-by: Josh <josh.t.richards@gmail.com>
Replace tentative language with verified token-storage and validation behavior.

Clarify the consequences of missing recoverable passwords, tighten the security impact statements, and correct password-length boundary wording.

Signed-off-by: Josh <josh.t.richards@gmail.com>
Signed-off-by: Josh <josh.t.richards@gmail.com>
@github-actions

Copy link
Copy Markdown
Contributor

📖 Documentation Preview

🔍 Open preview →

📄 1 changed documentation page

Last updated: Fri, 25 Sep 2026 14:53:58 GMT

@joshtrichards
joshtrichards merged commit 5119f7f into stable33 Sep 27, 2026
23 checks passed
@joshtrichards
joshtrichards deleted the backport/15476/stable33 branch September 27, 2026 01:00
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant