Changing verify_password so it works like verify_and_update_password. Currently verify_password was not only creating a hmac hash but also encrypting (encrypt_password is first hmac-signing and then encrypting).

Removed unneccessary and wrong tests.
This commit is contained in:
Ahti Kitsik
2014-02-20 16:46:49 +02:00
parent 0268a2d568
commit 1395df334e
2 changed files with 17 additions and 1 deletions
+13
View File
@@ -20,6 +20,19 @@ from flask_security.signals import user_registered
from tests import SecurityTest
class PasswordVerifyEncryptTests(SecurityTest):
AUTH_CONFIG = {
'SECURITY_PASSWORD_HASH': 'bcrypt',
'SECURITY_PASSWORD_SALT': '89gf828uiguiu23ju2'
}
def test_verify_password_bcrypt(self):
from flask_security.utils import verify_password, encrypt_password
with self.app.app_context():
self.assertTrue(verify_password('custompassword', encrypt_password('custompassword')))
class ConfiguredPasswordHashSecurityTests(SecurityTest):
AUTH_CONFIG = {