
Security News
Researcher Exposes Zero-Day Clickjacking Vulnerabilities in Major Password Managers
Hacker Demonstrates How Easy It Is To Steal Data From Popular Password Managers
sequel_secure_password
Advanced tools
Plugin adds BCrypt authentication and password hashing to Sequel models.
Model using this plugin should have password_digest
field.
This plugin was created by extracting has_secure_password
strategy from rails.
Add this line to your application's Gemfile:
gem 'sequel_secure_password'
And then execute:
$ bundle
Or install it yourself as:
$ gem install sequel_secure_password
Plugin should be used in subclasses of Sequel::Model
.
Always call super in validate
method of your model, otherwise password
validations won't be executed.
It does not set_allowed_columns
and mass assignment policy must be managed
separately.
Example model:
class User < Sequel::Model
plugin :secure_password
end
# cost option can be used to change computational complexity of BCrypt
class HighCostUser < Sequel::Model
plugin :secure_password, cost: 12
end
# include_validations option can be used to disable default password
# presence and confirmation
class UserWithoutValidations < Sequel::Model
plugin :secure_password, include_validations: false
end
# digest_column option can be used to use an alternate database column.
# the default column is "password_digest"
class UserWithAlternateDigestColumn < Sequel::Model
plugin :secure_password, digest_column: :password_hash
end
user = User.new
user.password = "foo"
user.password_confirmation = "bar"
user.valid? # => false
user.password_confirmation = "foo"
user.valid? # => true
user.authenticate("foo") # => user
user.authenticate("bar") # => nil
:cost
option;:include_validations
option.FAQs
Unknown package
We found that sequel_secure_password demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Security News
Hacker Demonstrates How Easy It Is To Steal Data From Popular Password Managers
Security News
Oxlint’s new preview brings type-aware linting powered by typescript-go, combining advanced TypeScript rules with native-speed performance.
Security News
A new site reviews software projects to reveal if they’re truly FOSS, making complex licensing and distribution models easy to understand.