Explorar el Código

Document NoOpPasswordEncoder will not be removed

This commit adds extension to deprecation notice.

Fixes gh-8506
Dávid Kovács hace 5 años
padre
commit
a9c8b350b8

+ 2 - 1
crypto/src/main/java/org/springframework/security/crypto/password/NoOpPasswordEncoder.java

@@ -26,7 +26,8 @@ package org.springframework.security.crypto.password;
  * @deprecated This PasswordEncoder is not secure. Instead use an
  * adaptive one way function like BCryptPasswordEncoder, Pbkdf2PasswordEncoder, or
  * SCryptPasswordEncoder. Even better use {@link DelegatingPasswordEncoder} which supports
- * password upgrades.
+ * password upgrades. There are no plans to remove this support. It is deprecated to indicate that
+ * this is a legacy implementation and using it is considered insecure.
  */
 @Deprecated
 public final class NoOpPasswordEncoder implements PasswordEncoder {