fix(bcrypt): require version 2 for sha256 digests - #355
Conversation
|
Navigate logical layers of code changes, visualize relationships, and explore their blast radius. No actionable comments were generated in the recent review. 🎉 ℹ️ Recent review info⚙️ Run configurationConfiguration used: defaults Review profile: CHILL Plan: Advanced Run ID: 📒 Files selected for processing (3)
Included review availability: Your plan provides up to 1 included review per hour; 0 remain after this review. 📝 WalkthroughWalkthroughSHA256 bcrypt decoding now requires an explicit version 2 option. The decoder rejects hashes with a missing or unsupported version. Regression tests cover rejected versions and successful version-2 decoding. ChangesSHA256 bcrypt version validation
Priority: ⬇️ Low Estimated code review effort: 2 (Simple) | ~10 minutes Change: Bug fix Merge Risk: ⚪ Minimal · up to The decoder’s version checks match the format emitted by the encoder, with no identified issue requiring resolution before merge. 🚥 Pre-merge checks | ✅ 4 | ❌ 1❌ Failed checks (1 warning)
✅ Passed checks (4 passed)
✨ Finishing Touches 💡 1📝 Generate docstrings 💡
🧪 Generate unit tests (beta)
Warning Some tools did not complete. Review the errors below. 🔧 golangci-lint (2.13.2)Error: can't load config: unsupported version of the configuration: "" See https://golangci-lint.run/docs/product/migration-guide for migration instructions Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
The SHA256 variant ignored the v parameter, so digests with any version, or none at all, were decoded as version 2 and encoded again as v=2. Only version 2 is implemented, where the password is hashed with HMAC-SHA256 keyed by the salt, so a digest claiming another version would be verified with the wrong algorithm. Decoding now returns ErrEncodedHashInvalidVersion unless the v parameter is present and equal to 2, which is the version this library and passlib encode. Digests in the passlib version 1 format use a different layout and were already rejected.
75ec0bd to
dc40db4
Compare
Codecov Report✅ All modified and coverable lines are covered by tests. Additional details and impacted files@@ Coverage Diff @@
## master #355 +/- ##
==========================================
+ Coverage 83.07% 83.19% +0.12%
==========================================
Files 49 49
Lines 1737 1744 +7
==========================================
+ Hits 1443 1451 +8
+ Misses 294 293 -1 ☔ View full report in Codecov by Harness. 🚀 New features to boost your workflow:
|
|
@coderabbitai full review |
✅ Action performedFull review finished. |
The SHA256 variant ignored the v parameter, so digests with any version, or none at all, were decoded as version 2 and encoded again as v=2. Only version 2 is implemented, where the password is hashed with HMAC-SHA256 keyed by the salt, so a digest claiming another version would be verified with the wrong algorithm.
Decoding now returns ErrEncodedHashInvalidVersion unless the v parameter is present and equal to 2, which is the version this library and passlib encode. Digests in the passlib version 1 format use a different layout and were already rejected.
Summary by CodeRabbit