fix(auth): reject ill-formed local passwords
This commit is contained in:
@@ -53,6 +53,12 @@ function parsePHC(encoded: string): Argon2Parameters | undefined {
|
||||
|
||||
function passwordBytes(password: string): Buffer | undefined {
|
||||
if (typeof password !== "string") return undefined;
|
||||
const typedPassword = password as string & { isWellFormed?: () => boolean };
|
||||
if (typeof typedPassword.isWellFormed === "function") {
|
||||
if (!typedPassword.isWellFormed()) return undefined;
|
||||
} else if (/[\uD800-\uDFFF]/.test(password)) {
|
||||
return undefined;
|
||||
}
|
||||
const bytes = Buffer.from(password, "utf8");
|
||||
return bytes.length >= MINIMUM_PASSWORD_BYTES && bytes.length <= MAXIMUM_PASSWORD_BYTES ? bytes : undefined;
|
||||
}
|
||||
|
||||
Reference in New Issue
Block a user