package cabana import ( "testing" "golang.org/x/crypto/bcrypt" ) // TestMissingUserHashUsesConfiguredCost pins WR-12: a login for an unknown // identifier is checked against a hash at the configured bcrypt cost, so it // costs the same as a real admin's (whose hash is rehashed to that cost). func TestMissingUserHashUsesConfiguredCost(t *testing.T) { for _, cost := range []int{4, 6} { s := &service{bcryptCost: cost} hash := s.missingUserHash() got, err := bcrypt.Cost([]byte(hash)) if err != nil || got != cost { t.Fatalf("missing-user hash cost = %d, %v; want %d", got, err, cost) } if again := s.missingUserHash(); again != hash { t.Fatal("missing-user hash was rebuilt instead of reused") } } }