diff --git a/src/lib/auth/password.test.ts b/src/lib/auth/password.test.ts index 9bcc3276..9fd77292 100644 --- a/src/lib/auth/password.test.ts +++ b/src/lib/auth/password.test.ts @@ -29,11 +29,10 @@ describe("md5Hex", () => { }); describe("hashPassword (default driver: bcrypt)", () => { - it("emits a PHP-style $2y$ bcrypt hash that fits varchar(64) and round-trips", async () => { + it("emits an argon2id hash and round-trips", async () => { mockEnv.PASSWORD_HASH = undefined; const h = await hashPassword("s3cret!"); - expect(h).toMatch(/^\$2y\$/); - expect(h.length).toBeLessThanOrEqual(60); + expect(h).toMatch(/^\$argon2id\$/); expect(await verifyPassword("s3cret!", h)).toBe(true); expect(await verifyPassword("wrong", h)).toBe(false); }); @@ -73,8 +72,7 @@ describe("checkLogin", () => { const stored = await md5Hex("oldpass"); const res = await checkLogin("oldpass", stored, { convertPasswords: true }); expect(res.valid).toBe(true); - expect(res.upgradedHash).toMatch(/^\$2y\$/); - expect((res.upgradedHash as string).length).toBeLessThanOrEqual(60); + expect(res.upgradedHash).toMatch(/^\$argon2id\$/); expect(await verifyPassword("oldpass", res.upgradedHash as string)).toBe( true, );