mirror of
https://github.com/Sagit-chu/flvx.git
synced 2026-10-09 03:06:37 +08:00
fix: harden auth, config access, and backups
This commit is contained in:
@@ -0,0 +1,25 @@
|
||||
package security
|
||||
|
||||
import (
|
||||
"strings"
|
||||
|
||||
"golang.org/x/crypto/bcrypt"
|
||||
)
|
||||
|
||||
func HashPassword(plain string) (string, error) {
|
||||
hash, err := bcrypt.GenerateFromPassword([]byte(plain), bcrypt.DefaultCost)
|
||||
if err != nil {
|
||||
return "", err
|
||||
}
|
||||
return string(hash), nil
|
||||
}
|
||||
|
||||
func VerifyPassword(storedHash, plain string) (bool, bool) {
|
||||
if strings.HasPrefix(storedHash, "$2") {
|
||||
return bcrypt.CompareHashAndPassword([]byte(storedHash), []byte(plain)) == nil, false
|
||||
}
|
||||
if MD5(plain) == storedHash {
|
||||
return true, true
|
||||
}
|
||||
return false, false
|
||||
}
|
||||
@@ -0,0 +1,25 @@
|
||||
package security
|
||||
|
||||
import (
|
||||
"strings"
|
||||
"testing"
|
||||
)
|
||||
|
||||
func TestHashPasswordProducesBcrypt(t *testing.T) {
|
||||
hash, err := HashPassword("admin_user")
|
||||
if err != nil {
|
||||
t.Fatalf("HashPassword() error = %v", err)
|
||||
}
|
||||
if len(hash) < 50 || !strings.HasPrefix(hash, "$2") {
|
||||
t.Fatalf("expected bcrypt hash, got %q", hash)
|
||||
}
|
||||
if ok, legacy := VerifyPassword(hash, "admin_user"); !ok || legacy {
|
||||
t.Fatalf("VerifyPassword() = (%v,%v), want (true,false)", ok, legacy)
|
||||
}
|
||||
}
|
||||
|
||||
func TestVerifyPasswordAcceptsLegacyMD5(t *testing.T) {
|
||||
if ok, legacy := VerifyPassword("3c85cdebade1c51cf64ca9f3c09d182d", "admin_user"); !ok || !legacy {
|
||||
t.Fatalf("VerifyPassword() = (%v,%v), want (true,true)", ok, legacy)
|
||||
}
|
||||
}
|
||||
Reference in New Issue
Block a user