ADR 009: Save passwords only hashed and salted with Argon2id
Context
To ensure user passwords are stored securely, they should be hashed and salted before being saved in the database (QG2).
Decision Outcome
Argon2id will be used to hash and salt passwords before storing them in the database. It’s easily available with Spring Security and is currently recommended by OWASP.
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.