Fix FAB FastAPI PATCH users to respect FAB_PASSWORD_HASH_METHOD - #73110
Merged
Merged
Conversation
PR apache#65735 made the security manager honor FAB_PASSWORD_HASH_METHOD through _hash_password, but the FastAPI users service PATCH path still called werkzeug's generate_password_hash directly, so REST-API password updates were always hashed with the default method while CLI/UI updates used the configured one - producing mixed hash schemes in the DB and breaking deployments that rely on a specific method. Route the PATCH path through security_manager._hash_password and update the existing service test to assert the new contract.
vincbeck
approved these changes
Sep 14, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
What's changed
The FastAPI users service PATCH path now hashes new passwords through
security_manager._hash_passwordinstead of calling werkzeug'sgenerate_password_hashdirectly. The existing service test asserts the new contract.Why
#65735 made the security manager honor
FAB_PASSWORD_HASH_METHODvia_hash_password, but the FastAPI PATCH/users/{username}path was missed: REST-API password updates were always hashed with the default method while CLI/UI updates used the configured one, producing mixed hash schemes in the DB and breaking deployments that rely on a specific method (the exact problem class #65735 / #65728 fixed for the other paths).Testing
uv run pytest providers/fab/tests/unit/fab/auth_manager/api_fastapi/services/test_users.py→ 24 passed