package bouncer import "testing" func TestPasswordHashAndCheck(t *testing.T) { hash, err := HashPassword(10, "secret") if err != nil { t.Fatal(err) } if !CheckPassword(hash, "secret") { t.Fatal("matching password rejected") } if CheckPassword(hash, "wrong") { t.Fatal("wrong password accepted") } if CheckPassword("not-a-hash", "secret") { t.Fatal("malformed hash must not panic or match") } } func TestPasswordAcceptsPHPHash(t *testing.T) { // php -r 'echo password_hash("golem15-a1-check", PASSWORD_BCRYPT, ["cost"=>10]);' const phpHash = "$2y$10$vvjEAuqFJXs6lWVy1eo5FuTZZr84LrP8Oz2c6pzAw4f2pk6u2xV5W" if !CheckPassword(phpHash, "golem15-a1-check") { t.Fatal("PHP $2y$ hash rejected") } if CheckPassword(phpHash, "other") { t.Fatal("PHP hash matched the wrong password") } } func TestNeedsRehash(t *testing.T) { hash, err := HashPassword(10, "secret") if err != nil { t.Fatal(err) } if !NeedsRehash(hash, 12) { t.Fatal("lower cost must need rehash") } if NeedsRehash(hash, 10) || NeedsRehash(hash, 8) { t.Fatal("equal or higher cost must not need rehash") } if !NeedsRehash("not-a-hash", 10) { t.Fatal("unparseable hash must need rehash") } }