fix(09): WR-12 time a missing admin login at the configured bcrypt cost

This commit is contained in:
Jakub Zych
2026-10-01 21:17:37 +02:00
parent 3f476164f9
commit eb8c727790
2 changed files with 45 additions and 8 deletions

View File

@@ -0,0 +1,24 @@
package cabana
import (
"testing"
"golang.org/x/crypto/bcrypt"
)
// TestMissingUserHashUsesConfiguredCost pins WR-12: a login for an unknown
// identifier is checked against a hash at the configured bcrypt cost, so it
// costs the same as a real admin's (whose hash is rehashed to that cost).
func TestMissingUserHashUsesConfiguredCost(t *testing.T) {
for _, cost := range []int{4, 6} {
s := &service{bcryptCost: cost}
hash := s.missingUserHash()
got, err := bcrypt.Cost([]byte(hash))
if err != nil || got != cost {
t.Fatalf("missing-user hash cost = %d, %v; want %d", got, err, cost)
}
if again := s.missingUserHash(); again != hash {
t.Fatal("missing-user hash was rebuilt instead of reused")
}
}
}