refactor: full codebase overhaul — dead code removal, env validation, logger migration, date consolidation, Prisma schema cleanup, button consistency, useEffect deps, test coverage
- env.ts: added 10 missing Zod-validated env vars (imager, paypal currency, argon2/bcrypt params) - Migrated 6 modules from process.env to validated env.* (auth, proxy-auth, paypal, password, redis, imager, moderation, alert, logger) - Replaced console.warn/error with pino logger in 9 server-side modules - Removed 50+ dead exports (SWF wrappers, coalesceHotelName, signIn, isStaff re-export, formatTimestamp, Skeleton/SkeletonCard, 4 unused housekeeping sections) - Consolidated date formatting: 28 files migrated to shared formatDate() from @/lib/format-date - Wired 4 radio/settings API routes through cached siteSettings service instead of raw Prisma queries - Added getMany()/getAll() helpers to SiteSettings service - Removed 88 dead Prisma model definitions (schema 2763→1846 lines) - Created admin action-helper.ts with wrapAction() for standardized error handling - Fixed useEffect dependency arrays in 4 data-heavy components - Replaced raw btn CSS classes with shadcn Button component across admin pages - Stripped dead i18n namespaces (common, pages.client) from all 22 translation files - Removed 2 dead scripts (create-release.sh, check-local-imports.ts) - Fixed knip.json configuration - Added 7 new test suites: format-date, paypal, moderation, alert, webhook, action-helper, and fixed password.test.ts for env mocking - All 358 tests passing across 72 test files - TypeScript: 0 errors
This commit is contained in:
1 parent
12e4a07e48
commit
1acace49d0
150 files changed
+10210
-12272
No files matched your search
+14
-11
@@ -2,17 +2,22 @@ import { randomBytes } from "node:crypto";
|
||||
import { compare as bcryptCompare, hash as bcryptHash } from "bcrypt";
|
||||
import { argon2id, argon2Verify, md5 } from "hash-wasm";
|
||||
|
||||
import { env } from "@/env";
|
||||
|
||||
// AtomCMS hashing (config/hashing.php): argon2id with memory=65536 KiB, time=4,
|
||||
// threads=1; bcrypt rounds=12 as the legacy fallback. The game emulator
|
||||
// validates the SAME users.password hash, so these must match.
|
||||
const ARGON2_PARAMS = {
|
||||
parallelism: Number(process.env.ARGON2_PARALLELISM) || 1,
|
||||
iterations: Number(process.env.ARGON2_ITERATIONS) || 4,
|
||||
memorySize: Number(process.env.ARGON2_MEMORY_SIZE) || 65536, // KiB
|
||||
hashLength: 32,
|
||||
} as const;
|
||||
function argon2Params() {
|
||||
return {
|
||||
parallelism: env.ARGON2_PARALLELISM,
|
||||
iterations: env.ARGON2_ITERATIONS,
|
||||
memorySize: env.ARGON2_MEMORY_SIZE,
|
||||
hashLength: 32,
|
||||
} as const;
|
||||
}
|
||||
|
||||
function bcryptRounds(): number {
|
||||
return Number(process.env.BCRYPT_ROUNDS) || 12;
|
||||
return env.BCRYPT_ROUNDS;
|
||||
}
|
||||
|
||||
// Which algorithm hashPassword() emits for NEW/upgraded passwords.
|
||||
@@ -20,9 +25,7 @@ function bcryptRounds(): number {
|
||||
// - "argon2id": ~97-char PHC hash. Opt in with PASSWORD_HASH=argon2id.
|
||||
// verifyPassword() always accepts BOTH, so logins keep working either way.
|
||||
function hashDriver(): "bcrypt" | "argon2id" {
|
||||
return process.env.PASSWORD_HASH?.toLowerCase() === "argon2id"
|
||||
? "argon2id"
|
||||
: "bcrypt";
|
||||
return env.PASSWORD_HASH === "argon2id" ? "argon2id" : "bcrypt";
|
||||
}
|
||||
|
||||
/**
|
||||
@@ -48,7 +51,7 @@ export async function hashPassword(password: string): Promise<string> {
|
||||
password,
|
||||
salt: randomBytes(16),
|
||||
outputType: "encoded",
|
||||
...ARGON2_PARAMS,
|
||||
...argon2Params(),
|
||||
});
|
||||
}
|
||||
// native bcrypt emits $2a$/$2b$; normalise to the PHP-canonical $2y$ the
|
||||
|
||||
Reference in new issue
Block a user