On Thu, 1 Oct 2026 at 18:15, Matthew Weier O'Phinney
<[email protected]> wrote:
>
> If a hash already exists from a truncated password, it will continue to 
> validate. The only time this would raise the exception or error is when 
> hashing, which will typically be done once, when a user registers, or chooses 
> to change their password. Having an error condition here forces the 
> application developer to address the truncation issue when storing new hashes 
> only, and won't invalidate existing user hashes and login attempts.

Small correction. Rehashing is commonly done during login, not registration.

Reply via email to