fix(auth): bind current local registry and CORS

This commit is contained in:
2026-08-17 00:34:58 +02:00
parent c34e01e9b9
commit 94c2cd3709
15 changed files with 514 additions and 87 deletions
+22 -1
View File
@@ -9,7 +9,7 @@ vi.mock("node:crypto", async (importOriginal) => {
return { ...actual, argon2: argon2Spy };
});
import { verifyPassword } from "../src/auth/password.js";
import { isValidPasswordHash, verifyPassword } from "../src/auth/password.js";
interface Argon2Vector {
password: string;
@@ -76,6 +76,7 @@ describe("local Argon2id password verification", () => {
`$argon2id$v=19$m=65536,t=3,p=5$${salt}$${digest}`,
`$argon2id$v=19$m=65536,t=3,p=1$${salt}$${"A".repeat(88)}`,
`$argon2id$v=19$m=65536,t=3,p=1$${salt}=$${digest}`,
`$argon2id$v=19$m=8,t=1,p=1$${salt}$${digest}`,
];
for (const phc of cases) {
@@ -84,4 +85,24 @@ describe("local Argon2id password verification", () => {
expect(argon2Spy).not.toHaveBeenCalled();
}
});
test("accepts only the exact Go Argon2id policy in registry PHCs", () => {
const [empty, algorithm, version, parameters, salt, digest] = vectors[0].phc.split("$");
expect(empty).toBe("");
expect(algorithm).toBe("argon2id");
expect(version).toBe("v=19");
expect(isValidPasswordHash(`$${algorithm}$${version}$m=8,t=1,p=1$${salt}$${digest}`)).toBe(false);
expect(isValidPasswordHash(`$${algorithm}$${version}$m=65536,t=1,p=1$${salt}$${digest}`)).toBe(false);
expect(isValidPasswordHash(`$${algorithm}$${version}$m=65536,t=3,p=2$${salt}$${digest}`)).toBe(false);
expect(isValidPasswordHash(`$${algorithm}$${version}$${parameters}$${salt}$${digest}`)).toBe(true);
});
test("surfaces a sanitized operational error when native Argon2 fails", async () => {
argon2Spy.mockImplementationOnce((_algorithm, _parameters, callback) => {
callback(new Error("native details must not leave the verifier"));
});
await expect(verifyPassword(vectors[0].password, vectors[0].phc))
.rejects.toThrow("local_password_verification_failed");
});
});