Fix BCRYPT_ROUNDS override — use function to read env at call time
Deploy / release (push) Skipped
Deploy / deploy (push) Successful in 1m54s

BCRYPT_ROUNDS was a module-level const evaluated at import time,
so env overrides in tests or CI had no effect. Changed to function
that reads process.env on each call. Also lowered hardcoded
bcryptHash(..., 10) in test to use env var with fallback 4.

CI: BCRYPT_ROUNDS=2. Password test suite: 1860ms → 29ms.
This commit is contained in:
openhands committed 2026-07-23 19:30:47 +02:00
1 parent 331a18e9c7
commit 7dbca4117c
2 files changed
+6 -3

No files matched your search

+2 -1
View File
@@ -58,7 +58,8 @@ describe("hashPassword (PASSWORD_HASH=argon2id)", () => {
describe("bcrypt", () => {
it("verifies a bcrypt hash and accepts the PHP $2y$ prefix", async () => {
const h = await bcryptHash("hunter2", 10); // native bcrypt emits $2a$/$2b$
const rounds = Number(process.env.BCRYPT_ROUNDS) || 4;
const h = await bcryptHash("hunter2", rounds); // native bcrypt emits $2a$/$2b$
expect(await verifyPassword("hunter2", h)).toBe(true);
// PHP stores $2y$ — bcrypt must accept it as equivalent.
const phpStyle = h.replace(/^\$2[ab]\$/, "$2y$");