feat(auth): auto-upgrade every legacy password format to bcrypt on login
checkLogin now verifies and migrates all known password formats without configuration: bcrypt, argon2id/argon2i/argon2d, unsalted md5/sha1/sha256/ sha512, double-md5 (UberCMS/Butterfly), salted md5 with embedded salt (hash:salt, salt:hash, hash$salt), and a guarded plaintext fallback. Every successful legacy login rewrites the stored hash to bcrypt, so the CONVERT_PASSWORDS flag is no longer required (kept for deploy compatibility).
This commit is contained in:
1 parent
905573e627
commit
e153300da0
5 files changed
+326
-47
No files matched your search
+2
-2
@@ -69,8 +69,8 @@ const schema = z
|
||||
// Laravel APP_KEY (base64:...) — needed to read existing 2FA secrets.
|
||||
APP_KEY: z.string().optional(),
|
||||
|
||||
// Mirrors Laravel config('habbo.site.convert_passwords') — enables
|
||||
// legacy md5/argon2id hashes to be upgraded to bcrypt on login.
|
||||
// Deprecated: legacy md5/argon2id hashes are ALWAYS upgraded to bcrypt
|
||||
// on login now (no flag required). Kept for config compatibility.
|
||||
CONVERT_PASSWORDS: z
|
||||
.string()
|
||||
.optional()
|
||||
|
||||
Reference in new issue
Block a user