Files
summercms/bouncer/password_test.go
2026-09-22 13:36:08 +02:00

47 lines
1.2 KiB
Go

package bouncer
import "testing"
func TestPasswordHashAndCheck(t *testing.T) {
hash, err := HashPassword(10, "secret")
if err != nil {
t.Fatal(err)
}
if !CheckPassword(hash, "secret") {
t.Fatal("matching password rejected")
}
if CheckPassword(hash, "wrong") {
t.Fatal("wrong password accepted")
}
if CheckPassword("not-a-hash", "secret") {
t.Fatal("malformed hash must not panic or match")
}
}
func TestPasswordAcceptsPHPHash(t *testing.T) {
// php -r 'echo password_hash("golem15-a1-check", PASSWORD_BCRYPT, ["cost"=>10]);'
const phpHash = "$2y$10$vvjEAuqFJXs6lWVy1eo5FuTZZr84LrP8Oz2c6pzAw4f2pk6u2xV5W"
if !CheckPassword(phpHash, "golem15-a1-check") {
t.Fatal("PHP $2y$ hash rejected")
}
if CheckPassword(phpHash, "other") {
t.Fatal("PHP hash matched the wrong password")
}
}
func TestNeedsRehash(t *testing.T) {
hash, err := HashPassword(10, "secret")
if err != nil {
t.Fatal(err)
}
if !NeedsRehash(hash, 12) {
t.Fatal("lower cost must need rehash")
}
if NeedsRehash(hash, 10) || NeedsRehash(hash, 8) {
t.Fatal("equal or higher cost must not need rehash")
}
if !NeedsRehash("not-a-hash", 10) {
t.Fatal("unparseable hash must need rehash")
}
}