feat(auth): auto-upgrade every legacy password format to bcrypt on login
CI / check (push) Failing after 25s
CI / preflight (push) Skipped
CI / deploy (push) Skipped

checkLogin now verifies and migrates all known password formats without
configuration: bcrypt, argon2id/argon2i/argon2d, unsalted md5/sha1/sha256/
sha512, double-md5 (UberCMS/Butterfly), salted md5 with embedded salt
(hash:salt, salt:hash, hash$salt), and a guarded plaintext fallback.

Every successful legacy login rewrites the stored hash to bcrypt, so the
CONVERT_PASSWORDS flag is no longer required (kept for deploy compatibility).
This commit is contained in:
openhands committed 2026-09-17 14:56:31 +02:00
1 parent 905573e627
commit e153300da0
5 files changed
+326 -47

No files matched your search

+3 -2
View File
@@ -36,8 +36,9 @@ BADGE_URL=/swf/c_images/album1584
# --- SECURITY & HASHING ---
AUTH_SECRET=your-super-secret-auth-key-change-this-min-32-chars
APP_KEY=base64:your-app-key-here=
CONVERT_PASSWORDS=true
# CONVERT_PASSWORDS: enables legacy md5/argon2id -> bcrypt upgrade on login.
# Deprecated: legacy md5/argon2id hashes are ALWAYS upgraded to bcrypt on
# login now. Kept only for config compatibility with existing deploys.
# CONVERT_PASSWORDS=true
BCRYPT_COST=12
# --- PATHS ---