refactor(auth): remove obsolete CONVERT_PASSWORDS env var
CI / check (push) Successful in 4m25s
CI / preflight (push) Skipped
CI / deploy (push) Successful in 2m26s

Legacy md5/argon2id hashes are now always upgraded to bcrypt on login, so
the CONVERT_PASSWORDS flag is no longer used. Drop it from env schema,
.env.example, the docker installer, and test mocks.
This commit is contained in:
openhands committed 2026-09-17 15:01:23 +02:00
1 parent e153300da0
commit 2c0439db6a
6 files changed
+9 -14

No files matched your search

+1 -3
View File
@@ -36,9 +36,7 @@ BADGE_URL=/swf/c_images/album1584
# --- SECURITY & HASHING ---
AUTH_SECRET=your-super-secret-auth-key-change-this-min-32-chars
APP_KEY=base64:your-app-key-here=
# Deprecated: legacy md5/argon2id hashes are ALWAYS upgraded to bcrypt on
# login now. Kept only for config compatibility with existing deploys.
# CONVERT_PASSWORDS=true
# Bcrypt cost factor for new password hashes.
BCRYPT_COST=12
# --- PATHS ---
+1 -1
View File
@@ -78,7 +78,7 @@ else
[[ "$auth_secret" =~ ^[0-9a-f]{64}$ ]] || fail "Could not generate the authentication secret."
env_tmp="$(mktemp "$DIR/.env.install.XXXXXX")"
{
printf '%s\n' 'NODE_ENV=production' 'PORT=3002' 'NEXT_TELEMETRY_DISABLED=1' 'AUTH_TRUST_HOST=true' 'CONVERT_PASSWORDS=true'
printf '%s\n' 'NODE_ENV=production' 'PORT=3002' 'NEXT_TELEMETRY_DISABLED=1' 'AUTH_TRUST_HOST=true'
printf "HOTEL_NAME='%s'\nAPP_URL='%s'\nAUTH_URL='%s'\n" "$hotel" "$public_url" "$public_url"
printf "DATABASE_URL='%s'\nREDIS_URL='%s'\nAUTH_SECRET='%s'\n" "$database_url" "$redis_url" "$auth_secret"
printf "IMAGER_URL='%s'\nIMAGING_UPSTREAM_URL='%s'\nBADGE_URL='/swf/c_images/album1584'\n" "$imager_url" "$imager_url"
+1 -1
View File
@@ -17,7 +17,7 @@ const core = vi.hoisted(() => ({
}),
}));
vi.mock("@/env", () => ({ env: { CONVERT_PASSWORDS: false } }));
vi.mock("@/env", () => ({ env: {} }));
vi.mock("@/lib/auth/login-core", () => core);
vi.mock("@/lib/rate-limit", () => ({ clientIp: vi.fn(), rateLimit: vi.fn() }));
vi.mock("@/lib/services/captcha", () => ({
-6
View File
@@ -69,12 +69,6 @@ const schema = z
// Laravel APP_KEY (base64:...) — needed to read existing 2FA secrets.
APP_KEY: z.string().optional(),
// Deprecated: legacy md5/argon2id hashes are ALWAYS upgraded to bcrypt
// on login now (no flag required). Kept for config compatibility.
CONVERT_PASSWORDS: z
.string()
.optional()
.transform((v) => v === "true" || v === "1"),
// bcrypt cost factor used for new password hashes.
BCRYPT_COST: z.coerce.number().int().min(4).max(31).default(12),
// Filesystem dir the badge uploader writes <code>.gif into (the emulator's
+2 -2
View File
@@ -138,14 +138,14 @@ describe("isDoubleMd5Of", () => {
describe("isSaltedMd5Of", () => {
it("verifies md5(salt+password) with hash:salt layout", async () => {
const salt = "pepper123";
const stored = `${(await md5Hex(salt + "oldpass"))}:${salt}`;
const stored = `${await md5Hex(salt + "oldpass")}:${salt}`;
expect(await isSaltedMd5Of("oldpass", stored)).toBe(true);
expect(await isSaltedMd5Of("wrong", stored)).toBe(false);
});
it("verifies md5(password+salt) with hash:salt layout", async () => {
const salt = "pepper123";
const stored = `${(await md5Hex("oldpass" + salt))}:${salt}`;
const stored = `${await md5Hex("oldpass" + salt)}:${salt}`;
expect(await isSaltedMd5Of("oldpass", stored)).toBe(true);
});
+4 -1
View File
@@ -57,7 +57,10 @@ export async function isDoubleMd5Of(
stored: string,
): Promise<boolean> {
if (!/^[a-f0-9]{32}$/i.test(stored)) return false;
return (await md5Hex(await md5Hex(password))).toLowerCase() === stored.toLowerCase();
return (
(await md5Hex(await md5Hex(password))).toLowerCase() ===
stored.toLowerCase()
);
}
/**