47 lines
1.2 KiB
Go
47 lines
1.2 KiB
Go
package bouncer
|
|
|
|
import "testing"
|
|
|
|
func TestPasswordHashAndCheck(t *testing.T) {
|
|
hash, err := HashPassword(10, "secret")
|
|
if err != nil {
|
|
t.Fatal(err)
|
|
}
|
|
if !CheckPassword(hash, "secret") {
|
|
t.Fatal("matching password rejected")
|
|
}
|
|
if CheckPassword(hash, "wrong") {
|
|
t.Fatal("wrong password accepted")
|
|
}
|
|
if CheckPassword("not-a-hash", "secret") {
|
|
t.Fatal("malformed hash must not panic or match")
|
|
}
|
|
}
|
|
|
|
func TestPasswordAcceptsPHPHash(t *testing.T) {
|
|
// php -r 'echo password_hash("golem15-a1-check", PASSWORD_BCRYPT, ["cost"=>10]);'
|
|
const phpHash = "$2y$10$vvjEAuqFJXs6lWVy1eo5FuTZZr84LrP8Oz2c6pzAw4f2pk6u2xV5W"
|
|
if !CheckPassword(phpHash, "golem15-a1-check") {
|
|
t.Fatal("PHP $2y$ hash rejected")
|
|
}
|
|
if CheckPassword(phpHash, "other") {
|
|
t.Fatal("PHP hash matched the wrong password")
|
|
}
|
|
}
|
|
|
|
func TestNeedsRehash(t *testing.T) {
|
|
hash, err := HashPassword(10, "secret")
|
|
if err != nil {
|
|
t.Fatal(err)
|
|
}
|
|
if !NeedsRehash(hash, 12) {
|
|
t.Fatal("lower cost must need rehash")
|
|
}
|
|
if NeedsRehash(hash, 10) || NeedsRehash(hash, 8) {
|
|
t.Fatal("equal or higher cost must not need rehash")
|
|
}
|
|
if !NeedsRehash("not-a-hash", 10) {
|
|
t.Fatal("unparseable hash must need rehash")
|
|
}
|
|
}
|