refactor: switch password hashing from argon2 to bcrypt
- hashPassword now emits bcrypt (cost 12) instead of argon2id - checkLogin migrates legacy md5/argon2id hashes to bcrypt on sign-in - keep argon2id verification only as a one-time migration path - replace ARGON2_* env vars with BCRYPT_COST
This commit is contained in:
1 parent
6fc14b9b84
commit
30ed2b8ce2
4 files changed
+42
-53
No files matched your search
+2
-3
@@ -32,9 +32,8 @@ NEXT_PUBLIC_IMAGER_URL=http://localhost:3002/imaging
|
||||
AUTH_SECRET=your-super-secret-auth-key-change-this-min-32-chars
|
||||
APP_KEY=base64:your-app-key-here=
|
||||
CONVERT_PASSWORDS=true
|
||||
ARGON2_MEMORY_KB=65536
|
||||
ARGON2_ITERATIONS=4
|
||||
ARGON2_PARALLELISM=1
|
||||
# CONVERT_PASSWORDS: enables legacy md5/argon2id -> bcrypt upgrade on login.
|
||||
BCRYPT_COST=12
|
||||
|
||||
# --- PATHS ---
|
||||
BADGE_UPLOAD_DIR=./public/assets/images/badges
|
||||
|
||||
Reference in new issue
Block a user