Skip to content

fix(sha1crypt): apply the default salt length - #350

Merged
james-d-elliott merged 1 commit into
masterfrom
fix/sha1crypt-default-salt
Sep 24, 2026
Merged

james-d-elliott merged 1 commit into
masterfrom
fix/sha1crypt-default-salt

Conversation

@james-d-elliott

@james-d-elliott james-d-elliott commented Sep 24, 2026 •

Copy link
Copy Markdown
Member

SaltLengthMin was 0, so the hasher's check for an unset salt length (bytesSalt < SaltLengthMin) was never true and the default of 8 was never applied. As a result every digest produced with the default options had an empty salt, meaning identical passwords produced identical digests.

SaltLengthMin is now 1, matching the documented minimum for WithSaltLength. This also means WithSaltLength(0) and HashWithSalt with an empty salt now return an error. Existing digests with an empty salt can still be decoded and verified.

Summary by CodeRabbit

  • Bug Fixes
    • Salt values must now contain at least one character when creating a SHA-1 crypt hash; empty and overlong values are rejected with updated validation messages.
    • Existing hashes that contain an empty salt can still be decoded and verified.

SaltLengthMin was 0, so the hasher's check for an unset salt length
(bytesSalt < SaltLengthMin) was never true and the default of 8 was never
applied. As a result every digest produced with the default options had
an empty salt, meaning identical passwords produced identical digests.

SaltLengthMin is now 1, matching the documented minimum for
WithSaltLength. This also means WithSaltLength(0) and HashWithSalt with
an empty salt now return an error. Existing digests with an empty salt
can still be decoded and verified.
@james-d-elliott
james-d-elliott requested a review from a team as a code owner September 24, 2026 11:07
@coderabbitai

coderabbitai Bot commented Sep 24, 2026 •

Copy link
Copy Markdown

Review in Change Stack →

Navigate logical layers of code changes, visualize relationships, and explore their blast radius.

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: defaults

Review profile: CHILL

Plan: Advanced

Run ID: 1c0c419a-8970-4119-88f3-920be26e626e

📥 Commits

Reviewing files that changed from the base of the PR and between 4aa856f and 3d4dbbc.

📒 Files selected for processing (2)
  • algorithm/sha1crypt/const.go
  • algorithm/sha1crypt/sha1crypt_test.go

Included review availability: Your plan provides up to 1 included review per hour; 0 remain after this review.


📝 Walkthrough

Walkthrough

The sha1crypt package now sets the minimum salt length to one. Tests cover rejecting empty salts, generating default-length salts, and decoding digests that contain an empty salt.

Changes

SHA-1 crypt salt validation

Layer / File(s) Summary
Salt minimum and compatibility tests
algorithm/sha1crypt/const.go, algorithm/sha1crypt/sha1crypt_test.go
The minimum salt length is now one. Tests check empty-salt validation, default salt length and distinct encoded digests, and matching an earlier digest with an empty salt.

Priority: ➖ Normal

Estimated code review effort: 2 (Simple) | ~10 minutes

Change: Bug fix

Merge Risk: ⚪ Minimal · up to 3d4db

The salt-length change fixes default hashing while preserving verification of existing digests. No material merge-blocking risk remains.

🚥 Pre-merge checks | ✅ 4 | ❌ 1

❌ Failed checks (1 warning)

Check name Status Explanation Resolution
Docstring Coverage ⚠️ Warning Docstring coverage is 0.00% which is insufficient. The required threshold is 80.00%. Docstring coverage is scoped to functions touched by this diff. Analyzed 5 functions across 2 files. Write docstrings for the functions missing them to satisfy the coverage threshold.
✅ Passed checks (4 passed)
Check name Status Explanation
Description Check ✅ Passed Check skipped - CodeRabbit’s high-level summary is enabled.
Title check ✅ Passed The title clearly identifies the primary change: applying the default salt length in the sha1crypt implementation. It is concise and specific.
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.
  • Fix all pre-merge checks with AI
✨ Finishing Touches 💡 1
📝 Generate docstrings 💡
  • Commit to this branch
  • Create a new PR
🧪 Generate unit tests (beta)
  • Commit to this branch
  • Create a new PR

Warning

Some tools did not complete. Review the errors below.

🔧 golangci-lint (2.13.2)

Error: can't load config: unsupported version of the configuration: "" See https://golangci-lint.run/docs/product/migration-guide for migration instructions
The command is terminated due to an error: can't load config: unsupported version of the configuration: "" See https://golangci-lint.run/docs/product/migration-guide for migration instructions


Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@codecov

codecov Bot commented Sep 24, 2026 •

Copy link
Copy Markdown

Codecov Report

✅ All modified and coverable lines are covered by tests.
✅ Project coverage is 82.34%. Comparing base (6b59085) to head (3d4dbbc).
⚠️ Report is 3 commits behind head on master.

Additional details and impacted files
@@            Coverage Diff             @@
##           master     #350      +/-   ##
==========================================
+ Coverage   82.28%   82.34%   +0.05%     
==========================================
  Files          49       49              
  Lines        1716     1716              
==========================================
+ Hits         1412     1413       +1     
+ Misses        304      303       -1     

☔ View full report in Codecov by Harness.
📢 Have feedback on the report? Share it here.

🚀 New features to boost your workflow:
  • ❄️ Test Analytics: Detect flaky tests, report on failures, and find test suite problems.

@james-d-elliott

Copy link
Copy Markdown
Member Author

@coderabbitai full review

@coderabbitai

coderabbitai Bot commented Sep 24, 2026 •

Copy link
Copy Markdown
⚠️ Action not completed

Review rate limited.


Your included review limit is currently reached under our Fair Usage Limits Policy. This review may still proceed through usage-based billing if eligible. Your next included review will be available in 7 minutes.

@james-d-elliott

Copy link
Copy Markdown
Member Author

@coderabbitai full review

@coderabbitai

coderabbitai Bot commented Sep 24, 2026 •

Copy link
Copy Markdown
✅ Action performed

Full review finished.

@james-d-elliott
james-d-elliott merged commit 1f41082 into master Sep 24, 2026
13 checks passed
@james-d-elliott
james-d-elliott deleted the fix/sha1crypt-default-salt branch September 24, 2026 12:21
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant