refactor(auth): remove obsolete CONVERT_PASSWORDS env var
CI / check (push) Successful in 4m25s
CI / preflight (push) Skipped
CI / deploy (push) Successful in 2m26s

Legacy md5/argon2id hashes are now always upgraded to bcrypt on login, so
the CONVERT_PASSWORDS flag is no longer used. Drop it from env schema,
.env.example, the docker installer, and test mocks.
This commit is contained in:
openhands committed 2026-09-17 15:01:23 +02:00
1 parent e153300da0
commit 2c0439db6a
6 files changed
+9 -14

No files matched your search

+1 -3
View File
@@ -36,9 +36,7 @@ BADGE_URL=/swf/c_images/album1584
# --- SECURITY & HASHING ---
AUTH_SECRET=your-super-secret-auth-key-change-this-min-32-chars
APP_KEY=base64:your-app-key-here=
# Deprecated: legacy md5/argon2id hashes are ALWAYS upgraded to bcrypt on
# login now. Kept only for config compatibility with existing deploys.
# CONVERT_PASSWORDS=true
# Bcrypt cost factor for new password hashes.
BCRYPT_COST=12
# --- PATHS ---