fix(auth): bind request auth snapshots
This commit is contained in:
@@ -97,6 +97,16 @@ describe("local Argon2id password verification", () => {
|
||||
expect(isValidPasswordHash(`$${algorithm}$${version}$${parameters}$${salt}$${digest}`)).toBe(true);
|
||||
});
|
||||
|
||||
test("rejects raw-base64 PHCs with non-zero trailing bits", async () => {
|
||||
const nonCanonicalSalt = "$argon2id$v=19$m=65536,t=3,p=1$AAECAwQFBgcICQoLDA0ODx$DRo8ZSPI8G5OCvnFFapbVEjP69aDjy1Sw9i2743cPC4";
|
||||
const nonCanonicalDigest = "$argon2id$v=19$m=65536,t=3,p=1$AAECAwQFBgcICQoLDA0ODw$DRo8ZSPI8G5OCvnFFapbVEjP69aDjy1Sw9i2743cPC5";
|
||||
|
||||
for (const phc of [nonCanonicalSalt, nonCanonicalDigest]) {
|
||||
expect(isValidPasswordHash(phc)).toBe(false);
|
||||
await expect(verifyPassword(vectors[0].password, phc)).resolves.toBe(false);
|
||||
}
|
||||
});
|
||||
|
||||
test("surfaces a sanitized operational error when native Argon2 fails", async () => {
|
||||
argon2Spy.mockImplementationOnce((_algorithm, _parameters, callback) => {
|
||||
callback(new Error("native details must not leave the verifier"));
|
||||
|
||||
Reference in New Issue
Block a user