fix(auth): bound local password encoding
This commit is contained in:
@@ -59,8 +59,9 @@ function passwordBytes(password: string): Buffer | undefined {
|
||||
} else if (/[\uD800-\uDFFF]/.test(password)) {
|
||||
return undefined;
|
||||
}
|
||||
const bytes = Buffer.from(password, "utf8");
|
||||
return bytes.length >= MINIMUM_PASSWORD_BYTES && bytes.length <= MAXIMUM_PASSWORD_BYTES ? bytes : undefined;
|
||||
const byteLength = Buffer.byteLength(password, "utf8");
|
||||
if (byteLength < MINIMUM_PASSWORD_BYTES || byteLength > MAXIMUM_PASSWORD_BYTES) return undefined;
|
||||
return Buffer.from(password, "utf8");
|
||||
}
|
||||
|
||||
export function isValidPasswordHash(encoded: string): boolean {
|
||||
|
||||
Reference in New Issue
Block a user