feat: add auth utilities (Argon2, session tokens)

Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
This commit is contained in:
2026-03-26 11:54:35 -05:00
co-authored by Claude Opus 4.6
parent fdc27584c9
commit 86c1389d67
2 changed files with 51 additions and 0 deletions
+29
View File
@@ -0,0 +1,29 @@
import { describe, it, expect } from 'vitest';
import {
hashPassword, verifyPassword, generateSessionToken, hashSessionToken
} from '$lib/server/auth-utils';
describe('auth-utils', () => {
it('hashes and verifies a password', async () => {
const hash = await hashPassword('testpassword');
expect(hash).not.toBe('testpassword');
expect(await verifyPassword(hash, 'testpassword')).toBe(true);
expect(await verifyPassword(hash, 'wrongpassword')).toBe(false);
});
it('generates unique session tokens', () => {
const token1 = generateSessionToken();
const token2 = generateSessionToken();
expect(token1).toHaveLength(64);
expect(token2).toHaveLength(64);
expect(token1).not.toBe(token2);
});
it('hashes session tokens deterministically', () => {
const token = generateSessionToken();
const hash1 = hashSessionToken(token);
const hash2 = hashSessionToken(token);
expect(hash1).toBe(hash2);
expect(hash1).not.toBe(token);
});
});