Users: add a validation step which lets the user's password be a Argon2 hashed sha1 hash.

OWASP suggests expiring all passwords and requiring users to update their password. However, we don't have a way to do this. They suggest this mechanism as a good alternative: https://cheatsheetseries.owasp.org/cheatsheets/Password_Storage_Cheat_Sheet.html#upgrading-legacy-hashes

Created by  Graham Christensen  on April 16, 2021
HY2SSCWGFZWIEV7KXAEMFDT3OC7DQANSNZCAGHFGGE3VJX4RDAMAC
Change contents