refactor(auth): remove obsolete CONVERT_PASSWORDS env var
Legacy md5/argon2id hashes are now always upgraded to bcrypt on login, so the CONVERT_PASSWORDS flag is no longer used. Drop it from env schema, .env.example, the docker installer, and test mocks.
This commit is contained in:
1 parent
e153300da0
commit
2c0439db6a
6 files changed
+9
-14
No files matched your search
@@ -138,14 +138,14 @@ describe("isDoubleMd5Of", () => {
|
||||
describe("isSaltedMd5Of", () => {
|
||||
it("verifies md5(salt+password) with hash:salt layout", async () => {
|
||||
const salt = "pepper123";
|
||||
const stored = `${(await md5Hex(salt + "oldpass"))}:${salt}`;
|
||||
const stored = `${await md5Hex(salt + "oldpass")}:${salt}`;
|
||||
expect(await isSaltedMd5Of("oldpass", stored)).toBe(true);
|
||||
expect(await isSaltedMd5Of("wrong", stored)).toBe(false);
|
||||
});
|
||||
|
||||
it("verifies md5(password+salt) with hash:salt layout", async () => {
|
||||
const salt = "pepper123";
|
||||
const stored = `${(await md5Hex("oldpass" + salt))}:${salt}`;
|
||||
const stored = `${await md5Hex("oldpass" + salt)}:${salt}`;
|
||||
expect(await isSaltedMd5Of("oldpass", stored)).toBe(true);
|
||||
});
|
||||
|
||||
|
||||
@@ -57,7 +57,10 @@ export async function isDoubleMd5Of(
|
||||
stored: string,
|
||||
): Promise<boolean> {
|
||||
if (!/^[a-f0-9]{32}$/i.test(stored)) return false;
|
||||
return (await md5Hex(await md5Hex(password))).toLowerCase() === stored.toLowerCase();
|
||||
return (
|
||||
(await md5Hex(await md5Hex(password))).toLowerCase() ===
|
||||
stored.toLowerCase()
|
||||
);
|
||||
}
|
||||
|
||||
/**
|
||||
|
||||
Reference in new issue
Block a user