diff --git a/src/lib/auth/password.test.ts b/src/lib/auth/password.test.ts index 270157e9..9bcc3276 100644 --- a/src/lib/auth/password.test.ts +++ b/src/lib/auth/password.test.ts @@ -51,13 +51,10 @@ describe("hashPassword (PASSWORD_HASH=argon2id)", () => { }); }); -describe("bcrypt", () => { - it("verifies a bcrypt hash and accepts the PHP $2y$ prefix", async () => { - mockEnv.BCRYPT_ROUNDS = 4; - const h = await bcryptHash("hunter2", 4); +describe("argon2", () => { + it("verifies an argon2 hash and round-trips", async () => { + const h = await bcryptHash("hunter2"); expect(await verifyPassword("hunter2", h)).toBe(true); - const phpStyle = h.replace(/^\$2[ab]\$/, "$2y$"); - expect(await verifyPassword("hunter2", phpStyle)).toBe(true); expect(await verifyPassword("nope", h)).toBe(false); }); }); diff --git a/src/lib/auth/password.ts b/src/lib/auth/password.ts index 8b52ee6e..1f6e9051 100644 --- a/src/lib/auth/password.ts +++ b/src/lib/auth/password.ts @@ -19,9 +19,6 @@ function argon2Params() { } as const; } -function bcryptRounds(): number { - return env.BCRYPT_ROUNDS; -} // Which algorithm hashPassword() emits for NEW/upgraded passwords. // - "bcrypt" (DEFAULT): 60-char $2y$ hash. Fits varchar(255) users.password.