[1.8.x] Fixed #24556 -- Added reminder about HTTPS to passwords docs.
Backport of 1119063c69
from master
This commit is contained in:
parent
7ae7600d2b
commit
5cc0407e45
|
@ -8,6 +8,14 @@ tools for managing user passwords. This document describes how Django stores
|
|||
passwords, how the storage hashing can be configured, and some utilities to
|
||||
work with hashed passwords.
|
||||
|
||||
.. seealso::
|
||||
|
||||
Even though users may use strong passwords, attackers might be able to
|
||||
eavesdrop on their connections. Use :ref:`HTTPS
|
||||
<security-recommendation-ssl>` to avoid sending passwords (or any other
|
||||
sensitive data) over plain HTTP connections because they will be vulnerable
|
||||
to password sniffing.
|
||||
|
||||
.. _auth_password_storage:
|
||||
|
||||
How Django stores passwords
|
||||
|
|
Loading…
Reference in New Issue