Browse Source

Remove double salt in Pbkdf2PasswordEncoder

Issue gh-3930
vitaliy_kuzmich 9 years ago
parent
commit
5f658b3ffc

+ 2 - 2
crypto/src/main/java/org/springframework/security/crypto/password/Pbkdf2PasswordEncoder.java

@@ -101,7 +101,7 @@ public class Pbkdf2PasswordEncoder implements PasswordEncoder {
 	}
 
 	private byte[] encodeAndConcatenate(CharSequence rawPassword, byte[] salt) {
-		return concatenate(salt, encode(rawPassword, salt));
+		return encode(rawPassword, salt);
 	}
 
 	/**
@@ -130,4 +130,4 @@ public class Pbkdf2PasswordEncoder implements PasswordEncoder {
 			throw new IllegalStateException("Could not create hash", e);
 		}
 	}
-}
+}