mirror of
https://github.com/Sagit-chu/flvx.git
synced 2026-10-06 10:06:36 +08:00
fix: close remaining security remediation gaps
This commit is contained in:
@@ -23,3 +23,17 @@ func VerifyPassword(storedHash, plain string) (bool, bool) {
|
||||
}
|
||||
return false, false
|
||||
}
|
||||
|
||||
func IsLegacyPasswordHash(storedHash string) bool {
|
||||
storedHash = strings.TrimSpace(storedHash)
|
||||
if len(storedHash) != 32 {
|
||||
return false
|
||||
}
|
||||
for _, r := range storedHash {
|
||||
if (r >= '0' && r <= '9') || (r >= 'a' && r <= 'f') || (r >= 'A' && r <= 'F') {
|
||||
continue
|
||||
}
|
||||
return false
|
||||
}
|
||||
return true
|
||||
}
|
||||
|
||||
@@ -23,3 +23,16 @@ func TestVerifyPasswordAcceptsLegacyMD5(t *testing.T) {
|
||||
t.Fatalf("VerifyPassword() = (%v,%v), want (true,true)", ok, legacy)
|
||||
}
|
||||
}
|
||||
|
||||
func TestIsLegacyPasswordHash(t *testing.T) {
|
||||
if !IsLegacyPasswordHash("3c85cdebade1c51cf64ca9f3c09d182d") {
|
||||
t.Fatal("expected 32-char hex MD5 hash to be legacy")
|
||||
}
|
||||
hash, err := HashPassword("admin_user")
|
||||
if err != nil {
|
||||
t.Fatalf("HashPassword() error = %v", err)
|
||||
}
|
||||
if IsLegacyPasswordHash(hash) {
|
||||
t.Fatalf("expected bcrypt hash not to be legacy: %q", hash)
|
||||
}
|
||||
}
|
||||
|
||||
Reference in New Issue
Block a user