diff --git a/django/contrib/auth/hashers.py b/django/contrib/auth/hashers.py index 74717c0c5c..046b196181 100644 --- a/django/contrib/auth/hashers.py +++ b/django/contrib/auth/hashers.py @@ -353,7 +353,7 @@ class BCryptPasswordHasher(BCryptSHA256PasswordHasher): This hasher does not first hash the password which means it is subject to the 72 character bcrypt password truncation, most use cases should prefer - the BCryptSha512PasswordHasher. + the BCryptSHA256PasswordHasher. See: https://code.djangoproject.com/ticket/20138 """