Commit b7d7a1dd authored by catch's avatar catch
Browse files

Issue #3153085 by kim.pepper, longwave, alexpott, vijaycs85, catch: Deprecate...

Issue #3153085 by kim.pepper, longwave, alexpott, vijaycs85, catch: Deprecate user_password and move to Password Generator service
parent 7628e38b
Loading
Loading
Loading
Loading
+2 −0
Changes for core/core.services.yml: 2 added lines, 0 removed lines.
Original line number Diff line number Diff line
@@ -967,6 +967,8 @@ services:
  password:
    class: Drupal\Core\Password\PhpassHashedPassword
    arguments: [16]
  password_generator:
    class: Drupal\Core\Password\DefaultPasswordGenerator
  request_format_route_filter:
    class: Drupal\Core\Routing\RequestFormatRouteFilter
    tags:
+42 −0
Changes for core/lib/Drupal/Core/Password/DefaultPasswordGenerator.php: 42 added lines, 0 removed lines.
Original line number Diff line number Diff line
<?php

namespace Drupal\Core\Password;

/**
 * Provides a default password generator.
 */
class DefaultPasswordGenerator implements PasswordGeneratorInterface {

  /**
   * The allowed characters for the password.
   *
   * Note that the number 0 and the letter 'O' have been removed to avoid
   * confusion between the two. The same is true of 'I', 1, and 'l'.
   *
   * @var string
   */
  protected $allowedChars = 'abcdefghijkmnopqrstuvwxyzABCDEFGHJKLMNPQRSTUVWXYZ23456789';

  /**
   * Generates a password.
   *
   * @param int $length
   *   (optional) The length of the password.
   *
   * @return string
   *   The password.
   */
  public function generate(int $length = 10): string {
    // The maximum integer we want from random_int().
    $max = strlen($this->allowedChars) - 1;

    $pass = '';

    for ($i = 0; $i < $length; $i++) {
      $pass .= $this->allowedChars[random_int(0, $max)];
    }

    return $pass;
  }

}
+21 −0
Changes for core/lib/Drupal/Core/Password/PasswordGeneratorInterface.php: 21 added lines, 0 removed lines.
Original line number Diff line number Diff line
<?php

namespace Drupal\Core\Password;

/**
 * Interface for generating passwords.
 */
interface PasswordGeneratorInterface {

  /**
   * Generates a password.
   *
   * @param int $length
   *   (optional) The length of the password.
   *
   * @return string
   *   The password.
   */
  public function generate(int $length = 10): string;

}
+1 −1
Changes for core/modules/dblog/tests/src/Functional/DbLogTest.php: 1 added line, 1 removed line.
Original line number Diff line number Diff line
@@ -410,7 +410,7 @@ private function verifyLinkEscaping() {
  private function doUser() {
    // Set user variables.
    $name = $this->randomMachineName();
    $pass = user_password();
    $pass = \Drupal::service('password_generator')->generate();
    // Add a user using the form to generate an add user event (which is not
    // triggered by drupalCreateUser).
    $edit = [];
+1 −1
Changes for core/modules/jsonapi/tests/src/Functional/UserTest.php: 1 added line, 1 removed line.
Original line number Diff line number Diff line
@@ -364,7 +364,7 @@ public function testPatchSecurityOtherUser() {
  public function testGetMailFieldOnlyVisibleToOwner() {
    // Create user B, with the same roles (and hence permissions) as user A.
    $user_a = $this->account;
    $pass = user_password();
    $pass = \Drupal::service('password_generator')->generate();
    $user_b = User::create([
      'name' => 'sibling-of-' . $user_a->getAccountName(),
      'mail' => 'sibling-of-' . $user_a->getAccountName() . '@example.com',
Loading