feat(auth): switch password hashing to argon2id with legacy auto-upgrade
CI / check (push) Failing after 10s
CI / release (push) Skipped
CI / deploy (push) Skipped

- hashPassword now emits argon2id (same params as the legacy AtomCMS
  Laravel setup: memory 64MB, iterations 4, parallelism 1)
- legacy md5 and bcrypt hashes are verified and auto-upgraded to
  argon2id on successful login (CONVERT_PASSWORDS=true)
- replace BCRYPT_ROUNDS env with ARGON2_MEMORY_KB / ARGON2_ITERATIONS /
  ARGON2_PARALLELISM
- update README and add tests for argon2id and bcrypt upgrade paths
This commit is contained in:
openhands committed 2026-08-01 17:09:29 +02:00
1 parent d39738eb0d
commit c601ffbb76
6 files changed
+121 -28

No files matched your search

+1 -1
View File
@@ -176,7 +176,7 @@ export const { handlers, signOut, auth } = NextAuth({
return null;
}
// Byte-compatible AtomCMS check (bcrypt + md5->bcrypt upgrade).
// Byte-compatible AtomCMS check (argon2id + legacy md5/bcrypt upgrade).
if (!user.password) return null;
const res = await checkLogin(password, user.password, {
convertPasswords: env.CONVERT_PASSWORDS,