Files
EpicNext-Cms/src/lib/auth
openhands ac60a867d9
CI / check (push) Failing after 30s
CI / preflight (push) Skipped
CI / deploy (push) Skipped
security: harden authentication (register/login)
- Username: restrict to [A-Za-z0-9_-], block reserved names (admin, mod, root, etc.),
  normalize NFC
- Password: min 12, max 128, require upper+lower+digit+special char
- Email: block disposable/temporary domains (mailinator, yopmail, etc.)
- Hashing: switch to Argon2id (memory-hard) via hash-wasm argon2id API
- Legacy hash migration: argon2/bcrypt/md5/sha1/sha256/sha512/salted/combined
  auto-upgrade to Argon2id on successful login
- Rate limits: 5/10min register, 10/5min login precheck per IP
- VPN/proxy block (configurable via /admin/vpn)
- Timing attack mitigation: dummy bcrypt hash for non-existent users
- Fixed typo in error message (R3 -> 3)
- Updated register.test.ts to match new validation rules
2026-09-21 19:33:13 +02:00
..
2026-07-13 21:57:41 +02:00
2026-07-13 21:57:41 +02:00
2026-07-13 21:57:41 +02:00