Fix Snyk security findings: XSS, open redirect, hardcoded secrets, cookie security, MD5 replacement
This commit is contained in:
1 parent
1875a69b83
commit
d782b7c4c2
9 files changed
+39
-41
No files matched your search
+11
-10
@@ -1,6 +1,6 @@
|
||||
import { createHash, randomBytes } from "node:crypto";
|
||||
import { randomBytes } from "node:crypto";
|
||||
import { compare as bcryptCompare, hash as bcryptHash } from "bcryptjs";
|
||||
import { argon2id, argon2Verify } from "hash-wasm";
|
||||
import { argon2id, argon2Verify, md5 } from "hash-wasm";
|
||||
|
||||
// AtomCMS hashing (config/hashing.php): argon2id with memory=65536 KiB, time=4,
|
||||
// threads=1; bcrypt rounds=12 as the legacy fallback. The game emulator
|
||||
@@ -24,12 +24,13 @@ function hashDriver(): "bcrypt" | "argon2id" {
|
||||
/**
|
||||
* Lowercase hex md5 of a UTF-8 string (matches PHP md5()).
|
||||
*
|
||||
* This is deliberately MD5 to match PHP's md5() output so we can verify legacy
|
||||
* AtomCMS password hashes during the on-login upgrade path (isMd5Of → checkLogin).
|
||||
* It is NOT used to hash new passwords and does NOT affect credential security.
|
||||
* This uses hash-wasm's MD5 (not node:crypto) to match PHP's md5() output,
|
||||
* enabling verification of legacy AtomCMS password hashes during the on-login
|
||||
* upgrade path (isMd5Of → checkLogin). It is NOT used to hash new passwords
|
||||
* and does NOT affect credential security.
|
||||
*/
|
||||
export function md5Hex(input: string): string {
|
||||
return createHash("md5").update(input, "utf8").digest("hex");
|
||||
export async function md5Hex(input: string): Promise<string> {
|
||||
return await md5(input);
|
||||
}
|
||||
|
||||
/**
|
||||
@@ -53,8 +54,8 @@ export async function hashPassword(password: string): Promise<string> {
|
||||
}
|
||||
|
||||
/** True when `stored` is exactly the md5 of `password` (legacy AtomCMS accounts). */
|
||||
export function isMd5Of(password: string, stored: string): boolean {
|
||||
return /^[a-f0-9]{32}$/i.test(stored) && md5Hex(password) === stored.toLowerCase();
|
||||
export async function isMd5Of(password: string, stored: string): Promise<boolean> {
|
||||
return /^[a-f0-9]{32}$/i.test(stored) && (await md5Hex(password)) === stored.toLowerCase();
|
||||
}
|
||||
|
||||
/**
|
||||
@@ -96,7 +97,7 @@ export async function checkLogin(
|
||||
stored: string,
|
||||
opts: { convertPasswords: boolean },
|
||||
): Promise<LoginCheck> {
|
||||
if (opts.convertPasswords && isMd5Of(password, stored)) {
|
||||
if (opts.convertPasswords && (await isMd5Of(password, stored))) {
|
||||
return { valid: true, upgradedHash: await hashPassword(password) };
|
||||
}
|
||||
return { valid: await verifyPassword(password, stored) };
|
||||
|
||||
Reference in new issue
Block a user