Default password hashing to bcrypt (fits varchar(64) users.password)

Verified against the live AtomCMS DB: users.password is varchar(64), so
argon2id (~97 chars) overflows the column and registration/upgrade fail
with 'value too long'. bcrypt (60-char $2y$) fits and matches the
existing accounts. hashPassword() now emits bcrypt by default; set
PASSWORD_HASH=argon2id to opt back in (needs a widened column).
verifyPassword() still accepts both, so existing logins keep working.

Verified end-to-end against the live DB: bcrypt $2y$ login round-trips
(correct=true, wrong=false). tsc 0, vitest 8/8 (password suite).
This commit is contained in:
Simo committed 2026-06-28 16:26:33 +02:00
1 parent d5efbba9f6
commit 4eccd146ba
3 files changed
+71 -19

No files matched your search

+5
View File
@@ -17,6 +17,11 @@ AUTH_SECRET=
APP_KEY=
CONVERT_PASSWORDS=false
# Password hashing for NEW/upgraded passwords: "bcrypt" (default; 60-char $2y$,
# fits a varchar(64) users.password) or "argon2id" (~97 chars, needs a wider
# column). Existing accounts in either format still verify on login.
PASSWORD_HASH=bcrypt
# RCON link to the Arcturus emulator
RCON_HOST=127.0.0.1
RCON_PORT=3001