Skip to content

Requiring longer passwords

Compare
Choose a tag to compare
@mark-bradshaw mark-bradshaw released this 03 Feb 16:37
· 121 commits to master since this release

Starting with Hapi 13 and Statehood 4 the password requirement for Iron encrypted cookies is now a minimum of 32 characters. The intention of increasing the size requirement is to make brute force guessing of your cookie password harder. Please update your app configuration to include a longer password if it is not already 32 characters long, or your server will not start.