Remove argon2id, use bcrypt-only password hashing

This commit is contained in:
openhands committed 2026-07-29 22:50:17 +02:00
1 parent 7f58e428ed
commit 7cdb785218
8 files changed
+14 -124

No files matched your search

+1 -7
View File
@@ -50,17 +50,11 @@ const schema = z
// Laravel APP_KEY (base64:...) — needed to read existing 2FA secrets.
APP_KEY: z.string().optional(),
// Mirrors Laravel config('habbo.site.convert_passwords') — enables md5->argon2id.
// Mirrors Laravel config('habbo.site.convert_passwords') — enables md5->bcrypt upgrade.
CONVERT_PASSWORDS: z
.string()
.optional()
.transform((v) => v === "true" || v === "1"),
// Hashing driver for NEW passwords: bcrypt (default, fits varchar(64)) | argon2id.
PASSWORD_HASH: z.enum(["bcrypt", "argon2id"]).optional(),
// Argon2id parameters (mirrors config/hashing.php).
ARGON2_PARALLELISM: z.coerce.number().int().positive().default(1),
ARGON2_ITERATIONS: z.coerce.number().int().positive().default(4),
ARGON2_MEMORY_SIZE: z.coerce.number().int().positive().default(65536),
// Bcrypt cost factor (rounds).
BCRYPT_ROUNDS: z.coerce.number().int().positive().default(12),
// Filesystem dir the badge uploader writes <code>.gif into (the emulator's