fix: [ Aegon fix]

This commit is contained in:
openhands committed 2026-07-28 21:26:31 +02:00
1 parent 738d7b8223
commit 5b9e2166df
2 files changed
+40 -18

No files matched your search

+15 -10
View File
@@ -1,9 +1,11 @@
import { randomBytes } from "node:crypto";
import { hash, verify } from "@node-rs/argon2";
import { argon2id, argon2Verify, md5 } from "hash-wasm";
export const bcryptHash = (password: string) => hash(password);
export const bcryptCompare = (password: string, hash: string) => verify(hash, password);
import {
argon2id,
argon2Verify,
bcrypt,
bcryptVerify,
md5,
} from "hash-wasm";
import { env } from "@/env";
@@ -54,9 +56,14 @@ export async function hashPassword(password: string): Promise<string> {
...argon2Params(),
});
}
// native bcrypt emits $2a$/$2b$; normalise to the PHP-canonical $2y$ the
// hash-wasm bcrypt emits $2a$; normalise to the PHP-canonical $2y$ the
// emulator and existing AtomCMS rows use.
const h = await bcryptHash(password);
const h = await bcrypt({
password,
salt: randomBytes(16),
costFactor: env.BCRYPT_ROUNDS,
outputType: "encoded",
});
return h.replace(/^\$2[ab]\$/, "$2y$");
}
@@ -89,9 +96,7 @@ export async function verifyPassword(
}
if (/^\$2[aby]\$/.test(stored)) {
try {
// PHP/AtomCMS store $2y$; native bcrypt only accepts $2a$/$2b$.
const normalized = stored.replace(/^\$2y\$/, "$2a$");
return await bcryptCompare(password, normalized);
return await bcryptVerify({ password, hash: stored });
} catch {
return false;
}