refactor(auth): remove obsolete CONVERT_PASSWORDS env var
CI / check (push) Successful in 4m25s
CI / preflight (push) Skipped
CI / deploy (push) Successful in 2m26s

Legacy md5/argon2id hashes are now always upgraded to bcrypt on login, so
the CONVERT_PASSWORDS flag is no longer used. Drop it from env schema,
.env.example, the docker installer, and test mocks.
This commit is contained in:
openhands committed 2026-09-17 15:01:23 +02:00
1 parent e153300da0
commit 2c0439db6a
6 files changed
+9 -14

No files matched your search

-6
View File
@@ -69,12 +69,6 @@ const schema = z
// Laravel APP_KEY (base64:...) — needed to read existing 2FA secrets.
APP_KEY: z.string().optional(),
// Deprecated: legacy md5/argon2id hashes are ALWAYS upgraded to bcrypt
// on login now (no flag required). Kept for config compatibility.
CONVERT_PASSWORDS: z
.string()
.optional()
.transform((v) => v === "true" || v === "1"),
// bcrypt cost factor used for new password hashes.
BCRYPT_COST: z.coerce.number().int().min(4).max(31).default(12),
// Filesystem dir the badge uploader writes <code>.gif into (the emulator's