Fix BCRYPT_ROUNDS override — use function to read env at call time
Deploy / release (push) Skipped
Deploy / deploy (push) Successful in 1m54s

BCRYPT_ROUNDS was a module-level const evaluated at import time,
so env overrides in tests or CI had no effect. Changed to function
that reads process.env on each call. Also lowered hardcoded
bcryptHash(..., 10) in test to use env var with fallback 4.

CI: BCRYPT_ROUNDS=2. Password test suite: 1860ms → 29ms.
This commit is contained in:
openhands committed 2026-07-23 19:30:47 +02:00
1 parent 331a18e9c7
commit 7dbca4117c
2 files changed
+6 -3

No files matched your search

+2 -1
View File
@@ -58,7 +58,8 @@ describe("hashPassword (PASSWORD_HASH=argon2id)", () => {
describe("bcrypt", () => {
it("verifies a bcrypt hash and accepts the PHP $2y$ prefix", async () => {
const h = await bcryptHash("hunter2", 10); // native bcrypt emits $2a$/$2b$
const rounds = Number(process.env.BCRYPT_ROUNDS) || 4;
const h = await bcryptHash("hunter2", rounds); // native bcrypt emits $2a$/$2b$
expect(await verifyPassword("hunter2", h)).toBe(true);
// PHP stores $2y$ — bcrypt must accept it as equivalent.
const phpStyle = h.replace(/^\$2[ab]\$/, "$2y$");
+4 -2
View File
@@ -11,7 +11,9 @@ const ARGON2_PARAMS = {
memorySize: Number(process.env.ARGON2_MEMORY_SIZE) || 65536, // KiB
hashLength: 32,
} as const;
const BCRYPT_ROUNDS = 12;
function bcryptRounds(): number {
return Number(process.env.BCRYPT_ROUNDS) || 12;
}
// Which algorithm hashPassword() emits for NEW/upgraded passwords.
// - "bcrypt" (DEFAULT): 60-char $2y$ hash. Fits varchar(255) users.password.
@@ -51,7 +53,7 @@ export async function hashPassword(password: string): Promise<string> {
}
// native bcrypt emits $2a$/$2b$; normalise to the PHP-canonical $2y$ the
// emulator and existing AtomCMS rows use.
const h = await bcryptHash(password, BCRYPT_ROUNDS);
const h = await bcryptHash(password, bcryptRounds());
return h.replace(/^\$2[ab]\$/, "$2y$");
}