feat: add auth utilities (Argon2, session tokens)
Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
This commit is contained in:
@@ -0,0 +1,22 @@
|
||||
import { hash, verify } from '@node-rs/argon2';
|
||||
import crypto from 'crypto';
|
||||
|
||||
export async function hashPassword(password: string): Promise<string> {
|
||||
return hash(password);
|
||||
}
|
||||
|
||||
export async function verifyPassword(hashedPassword: string, password: string): Promise<boolean> {
|
||||
try {
|
||||
return await verify(hashedPassword, password);
|
||||
} catch {
|
||||
return false;
|
||||
}
|
||||
}
|
||||
|
||||
export function generateSessionToken(): string {
|
||||
return crypto.randomBytes(32).toString('hex');
|
||||
}
|
||||
|
||||
export function hashSessionToken(token: string): string {
|
||||
return crypto.createHash('sha256').update(token).digest('hex');
|
||||
}
|
||||
@@ -0,0 +1,29 @@
|
||||
import { describe, it, expect } from 'vitest';
|
||||
import {
|
||||
hashPassword, verifyPassword, generateSessionToken, hashSessionToken
|
||||
} from '$lib/server/auth-utils';
|
||||
|
||||
describe('auth-utils', () => {
|
||||
it('hashes and verifies a password', async () => {
|
||||
const hash = await hashPassword('testpassword');
|
||||
expect(hash).not.toBe('testpassword');
|
||||
expect(await verifyPassword(hash, 'testpassword')).toBe(true);
|
||||
expect(await verifyPassword(hash, 'wrongpassword')).toBe(false);
|
||||
});
|
||||
|
||||
it('generates unique session tokens', () => {
|
||||
const token1 = generateSessionToken();
|
||||
const token2 = generateSessionToken();
|
||||
expect(token1).toHaveLength(64);
|
||||
expect(token2).toHaveLength(64);
|
||||
expect(token1).not.toBe(token2);
|
||||
});
|
||||
|
||||
it('hashes session tokens deterministically', () => {
|
||||
const token = generateSessionToken();
|
||||
const hash1 = hashSessionToken(token);
|
||||
const hash2 = hashSessionToken(token);
|
||||
expect(hash1).toBe(hash2);
|
||||
expect(hash1).not.toBe(token);
|
||||
});
|
||||
});
|
||||
Reference in New Issue
Block a user