feat(security): enforce modern password hashing and a mandatory master key
Problem to solve
The default PasswordEncoder is RIPEMD-160, with no salt and no cost factor, and SecurityConfigProperties ships a masterKey with a default value hardcoded in source.
Further details
Impact on existing AWE 4 products (level 1 - Low): transparent rehashing happens on the first successful login: old hashes keep validating and migrate themselves. Password column length must be checked in each database's Flyway scripts. The master key should already be configured in any serious deployment.
Effort: S (1-2 days) Delivery phase: 1 (quick value, low impact — worth bringing forward if an audit finding requires it) Development order: 22 (Block 3 - Backend, though small enough to bring forward)
Proposal
- Register a
DelegatingPasswordEncoderwith BCrypt or Argon2 as the primary algorithm and current encoders kept as legacy - Require the master key from configuration and fail fast at startup if it is missing
- Verify password column length in Flyway scripts for every supported database
What does success look like, and how can we measure that?
- New passwords are hashed with BCrypt or Argon2 by default
- Existing RIPEMD-160 hashes keep validating and are transparently rehashed on next successful login
- Application startup fails with a clear error when no master key is configured
- Flyway scripts for all six supported databases accommodate the new hash length
Links / references
- Part of the AWE 5 evolution plan (initiative 10 of 27, development order 22).