fix: close remaining security remediation gaps

This commit is contained in:
sagitchu
2026-05-14 11:10:06 +08:00
parent f0facf6703
commit abf13bdac9
5 changed files with 182 additions and 23 deletions
@@ -23,3 +23,16 @@ func TestVerifyPasswordAcceptsLegacyMD5(t *testing.T) {
t.Fatalf("VerifyPassword() = (%v,%v), want (true,true)", ok, legacy)
}
}
func TestIsLegacyPasswordHash(t *testing.T) {
if !IsLegacyPasswordHash("3c85cdebade1c51cf64ca9f3c09d182d") {
t.Fatal("expected 32-char hex MD5 hash to be legacy")
}
hash, err := HashPassword("admin_user")
if err != nil {
t.Fatalf("HashPassword() error = %v", err)
}
if IsLegacyPasswordHash(hash) {
t.Fatalf("expected bcrypt hash not to be legacy: %q", hash)
}
}