refactor: full codebase overhaul — dead code removal, env validation, logger migration, date consolidation, Prisma schema cleanup, button consistency, useEffect deps, test coverage
- env.ts: added 10 missing Zod-validated env vars (imager, paypal currency, argon2/bcrypt params) - Migrated 6 modules from process.env to validated env.* (auth, proxy-auth, paypal, password, redis, imager, moderation, alert, logger) - Replaced console.warn/error with pino logger in 9 server-side modules - Removed 50+ dead exports (SWF wrappers, coalesceHotelName, signIn, isStaff re-export, formatTimestamp, Skeleton/SkeletonCard, 4 unused housekeeping sections) - Consolidated date formatting: 28 files migrated to shared formatDate() from @/lib/format-date - Wired 4 radio/settings API routes through cached siteSettings service instead of raw Prisma queries - Added getMany()/getAll() helpers to SiteSettings service - Removed 88 dead Prisma model definitions (schema 2763→1846 lines) - Created admin action-helper.ts with wrapAction() for standardized error handling - Fixed useEffect dependency arrays in 4 data-heavy components - Replaced raw btn CSS classes with shadcn Button component across admin pages - Stripped dead i18n namespaces (common, pages.client) from all 22 translation files - Removed 2 dead scripts (create-release.sh, check-local-imports.ts) - Fixed knip.json configuration - Added 7 new test suites: format-date, paypal, moderation, alert, webhook, action-helper, and fixed password.test.ts for env mocking - All 358 tests passing across 72 test files - TypeScript: 0 errors
This commit is contained in:
1 parent
12e4a07e48
commit
1acace49d0
150 files changed
+10210
-12272
No files matched your search
@@ -1,5 +1,18 @@
|
||||
import { hash as bcryptHash } from "bcrypt";
|
||||
import { describe, expect, it } from "vitest";
|
||||
import { describe, expect, it, vi } from "vitest";
|
||||
|
||||
const mockEnv = vi.hoisted(() => ({
|
||||
PASSWORD_HASH: undefined,
|
||||
ARGON2_PARALLELISM: 1,
|
||||
ARGON2_ITERATIONS: 4,
|
||||
ARGON2_MEMORY_SIZE: 65536,
|
||||
BCRYPT_ROUNDS: 12,
|
||||
}));
|
||||
|
||||
vi.mock("@/env", () => ({
|
||||
env: mockEnv,
|
||||
}));
|
||||
|
||||
import {
|
||||
checkLogin,
|
||||
hashPassword,
|
||||
@@ -17,51 +30,32 @@ describe("md5Hex", () => {
|
||||
|
||||
describe("hashPassword (default driver: bcrypt)", () => {
|
||||
it("emits a PHP-style $2y$ bcrypt hash that fits varchar(64) and round-trips", async () => {
|
||||
const prev = process.env.PASSWORD_HASH;
|
||||
delete process.env.PASSWORD_HASH; // exercise the default
|
||||
try {
|
||||
const h = await hashPassword("s3cret!");
|
||||
expect(h).toMatch(/^\$2y\$/);
|
||||
expect(h.length).toBeLessThanOrEqual(60); // fits varchar(64)
|
||||
expect(await verifyPassword("s3cret!", h)).toBe(true);
|
||||
expect(await verifyPassword("wrong", h)).toBe(false);
|
||||
} finally {
|
||||
if (prev === undefined) delete process.env.PASSWORD_HASH;
|
||||
else process.env.PASSWORD_HASH = prev;
|
||||
}
|
||||
mockEnv.PASSWORD_HASH = undefined;
|
||||
const h = await hashPassword("s3cret!");
|
||||
expect(h).toMatch(/^\$2y\$/);
|
||||
expect(h.length).toBeLessThanOrEqual(60);
|
||||
expect(await verifyPassword("s3cret!", h)).toBe(true);
|
||||
expect(await verifyPassword("wrong", h)).toBe(false);
|
||||
});
|
||||
});
|
||||
|
||||
describe("hashPassword (PASSWORD_HASH=argon2id)", () => {
|
||||
it("hashes with the AtomCMS params and round-trips", async () => {
|
||||
const prev = process.env.PASSWORD_HASH;
|
||||
const prevMem = process.env.ARGON2_MEMORY_SIZE;
|
||||
const prevIters = process.env.ARGON2_ITERATIONS;
|
||||
process.env.PASSWORD_HASH = "argon2id";
|
||||
process.env.ARGON2_MEMORY_SIZE = "1024";
|
||||
process.env.ARGON2_ITERATIONS = "1";
|
||||
try {
|
||||
const h = await hashPassword("s3cret!");
|
||||
expect(h).toMatch(/^\$argon2id\$v=19\$m=1024,t=1,p=1\$/);
|
||||
expect(await verifyPassword("s3cret!", h)).toBe(true);
|
||||
expect(await verifyPassword("wrong", h)).toBe(false);
|
||||
} finally {
|
||||
if (prev === undefined) delete process.env.PASSWORD_HASH;
|
||||
else process.env.PASSWORD_HASH = prev;
|
||||
if (prevMem === undefined) delete process.env.ARGON2_MEMORY_SIZE;
|
||||
else process.env.ARGON2_MEMORY_SIZE = prevMem;
|
||||
if (prevIters === undefined) delete process.env.ARGON2_ITERATIONS;
|
||||
else process.env.ARGON2_ITERATIONS = prevIters;
|
||||
}
|
||||
mockEnv.PASSWORD_HASH = "argon2id";
|
||||
mockEnv.ARGON2_MEMORY_SIZE = 1024;
|
||||
mockEnv.ARGON2_ITERATIONS = 1;
|
||||
const h = await hashPassword("s3cret!");
|
||||
expect(h).toMatch(/^\$argon2id\$v=19\$m=1024,t=1,p=1\$/);
|
||||
expect(await verifyPassword("s3cret!", h)).toBe(true);
|
||||
expect(await verifyPassword("wrong", h)).toBe(false);
|
||||
});
|
||||
});
|
||||
|
||||
describe("bcrypt", () => {
|
||||
it("verifies a bcrypt hash and accepts the PHP $2y$ prefix", async () => {
|
||||
const rounds = Number(process.env.BCRYPT_ROUNDS) || 4;
|
||||
const h = await bcryptHash("hunter2", rounds); // native bcrypt emits $2a$/$2b$
|
||||
mockEnv.BCRYPT_ROUNDS = 4;
|
||||
const h = await bcryptHash("hunter2", 4);
|
||||
expect(await verifyPassword("hunter2", h)).toBe(true);
|
||||
// PHP stores $2y$ — bcrypt must accept it as equivalent.
|
||||
const phpStyle = h.replace(/^\$2[ab]\$/, "$2y$");
|
||||
expect(await verifyPassword("hunter2", phpStyle)).toBe(true);
|
||||
expect(await verifyPassword("nope", h)).toBe(false);
|
||||
@@ -78,16 +72,13 @@ describe("isMd5Of", () => {
|
||||
|
||||
describe("checkLogin", () => {
|
||||
it("upgrades a legacy md5 hash to the configured hash when conversion is enabled", async () => {
|
||||
mockEnv.PASSWORD_HASH = undefined;
|
||||
const stored = await md5Hex("oldpass");
|
||||
const res = await checkLogin("oldpass", stored, { convertPasswords: true });
|
||||
expect(res.valid).toBe(true);
|
||||
// Default driver is bcrypt — the upgraded hash must fit varchar(64).
|
||||
expect(res.upgradedHash).toMatch(/^\$2y\$/);
|
||||
expect((res.upgradedHash as string).length).toBeLessThanOrEqual(60);
|
||||
// The upgraded hash verifies the same password.
|
||||
expect(await verifyPassword("oldpass", res.upgradedHash as string)).toBe(
|
||||
true,
|
||||
);
|
||||
expect(await verifyPassword("oldpass", res.upgradedHash as string)).toBe(true);
|
||||
});
|
||||
|
||||
it("does NOT upgrade md5 when conversion is disabled", async () => {
|
||||
@@ -100,6 +91,7 @@ describe("checkLogin", () => {
|
||||
});
|
||||
|
||||
it("validates an existing modern hash with no upgrade", async () => {
|
||||
mockEnv.PASSWORD_HASH = undefined;
|
||||
const stored = await hashPassword("modern");
|
||||
const res = await checkLogin("modern", stored, { convertPasswords: true });
|
||||
expect(res.valid).toBe(true);
|
||||
|
||||
+14
-11
@@ -2,17 +2,22 @@ import { randomBytes } from "node:crypto";
|
||||
import { compare as bcryptCompare, hash as bcryptHash } from "bcrypt";
|
||||
import { argon2id, argon2Verify, md5 } from "hash-wasm";
|
||||
|
||||
import { env } from "@/env";
|
||||
|
||||
// AtomCMS hashing (config/hashing.php): argon2id with memory=65536 KiB, time=4,
|
||||
// threads=1; bcrypt rounds=12 as the legacy fallback. The game emulator
|
||||
// validates the SAME users.password hash, so these must match.
|
||||
const ARGON2_PARAMS = {
|
||||
parallelism: Number(process.env.ARGON2_PARALLELISM) || 1,
|
||||
iterations: Number(process.env.ARGON2_ITERATIONS) || 4,
|
||||
memorySize: Number(process.env.ARGON2_MEMORY_SIZE) || 65536, // KiB
|
||||
hashLength: 32,
|
||||
} as const;
|
||||
function argon2Params() {
|
||||
return {
|
||||
parallelism: env.ARGON2_PARALLELISM,
|
||||
iterations: env.ARGON2_ITERATIONS,
|
||||
memorySize: env.ARGON2_MEMORY_SIZE,
|
||||
hashLength: 32,
|
||||
} as const;
|
||||
}
|
||||
|
||||
function bcryptRounds(): number {
|
||||
return Number(process.env.BCRYPT_ROUNDS) || 12;
|
||||
return env.BCRYPT_ROUNDS;
|
||||
}
|
||||
|
||||
// Which algorithm hashPassword() emits for NEW/upgraded passwords.
|
||||
@@ -20,9 +25,7 @@ function bcryptRounds(): number {
|
||||
// - "argon2id": ~97-char PHC hash. Opt in with PASSWORD_HASH=argon2id.
|
||||
// verifyPassword() always accepts BOTH, so logins keep working either way.
|
||||
function hashDriver(): "bcrypt" | "argon2id" {
|
||||
return process.env.PASSWORD_HASH?.toLowerCase() === "argon2id"
|
||||
? "argon2id"
|
||||
: "bcrypt";
|
||||
return env.PASSWORD_HASH === "argon2id" ? "argon2id" : "bcrypt";
|
||||
}
|
||||
|
||||
/**
|
||||
@@ -48,7 +51,7 @@ export async function hashPassword(password: string): Promise<string> {
|
||||
password,
|
||||
salt: randomBytes(16),
|
||||
outputType: "encoded",
|
||||
...ARGON2_PARAMS,
|
||||
...argon2Params(),
|
||||
});
|
||||
}
|
||||
// native bcrypt emits $2a$/$2b$; normalise to the PHP-canonical $2y$ the
|
||||
|
||||
Reference in new issue
Block a user