|
|
|
|
|
by CiPHPerCoder
2566 days ago
|
|
What if there wasn't a "next user login"? You'd hold onto insecure hashes possibly forever. Don't make this mistake. Rehash all of them up front. The details of whether or not users are forced to change their password is irrelevant to the escape route from this trap. |
|