feat(auth): switch password hashing to argon2id with legacy auto-upgrade
CI / check (push) Failing after 10s
CI / release (push) Skipped
CI / deploy (push) Skipped

- hashPassword now emits argon2id (same params as the legacy AtomCMS
  Laravel setup: memory 64MB, iterations 4, parallelism 1)
- legacy md5 and bcrypt hashes are verified and auto-upgraded to
  argon2id on successful login (CONVERT_PASSWORDS=true)
- replace BCRYPT_ROUNDS env with ARGON2_MEMORY_KB / ARGON2_ITERATIONS /
  ARGON2_PARALLELISM
- update README and add tests for argon2id and bcrypt upgrade paths
This commit is contained in:
openhands committed 2026-08-01 17:09:29 +02:00
1 parent d39738eb0d
commit c601ffbb76
6 files changed
+121 -28

No files matched your search

+6 -3
View File
@@ -50,13 +50,16 @@ const schema = z
// Laravel APP_KEY (base64:...) — needed to read existing 2FA secrets.
APP_KEY: z.string().optional(),
// Mirrors Laravel config('habbo.site.convert_passwords') — enables md5->bcrypt upgrade.
// Mirrors Laravel config('habbo.site.convert_passwords') — enables
// legacy md5/bcrypt hashes to be upgraded to argon2id on login.
CONVERT_PASSWORDS: z
.string()
.optional()
.transform((v) => v === "true" || v === "1"),
// Bcrypt cost factor (rounds).
BCRYPT_ROUNDS: z.coerce.number().int().positive().default(12),
// Argon2id parameters — defaults match the old AtomCMS (Laravel) setup.
ARGON2_MEMORY_KB: z.coerce.number().int().positive().default(65_536),
ARGON2_ITERATIONS: z.coerce.number().int().positive().default(4),
ARGON2_PARALLELISM: z.coerce.number().int().positive().default(1),
// Filesystem dir the badge uploader writes <code>.gif into (the emulator's
// badge image folder, e.g. .../assets/c_images/album1584). Upload is disabled
// when unset.