Fix password hashing for Workers runtime
This commit is contained in:
@@ -15,7 +15,8 @@ export type RequestPrincipal =
|
||||
|
||||
const SESSION_COOKIE = "koc_session";
|
||||
const SESSION_MAX_AGE_SECONDS = 60 * 60 * 24 * 7;
|
||||
const PASSWORD_ITERATIONS = 120_000;
|
||||
// Cloudflare Workers caps PBKDF2 at 100,000 iterations.
|
||||
const PASSWORD_ITERATIONS = 100_000;
|
||||
|
||||
function bytesToHex(bytes: Uint8Array) {
|
||||
return [...bytes].map((byte) => byte.toString(16).padStart(2, "0")).join("");
|
||||
|
||||
@@ -288,6 +288,7 @@ test("provides simple username-password login and three server-enforced roles",
|
||||
assert.match(logoutRoute, /deleteSession/);
|
||||
assert.match(logoutRoute, /clearSessionCookie/);
|
||||
assert.match(auth, /PBKDF2/);
|
||||
assert.match(auth, /PASSWORD_ITERATIONS = 100_000/);
|
||||
assert.match(auth, /HttpOnly/);
|
||||
assert.match(auth, /SameSite=Lax/);
|
||||
assert.match(auth, /SELECT id FROM users WHERE role = 'super_admin' LIMIT 1/);
|
||||
|
||||
Reference in New Issue
Block a user